CVE-2026-22723: Cloudfoundry Cf-Deployment

Medium severity, CVSS 6.5. EPSS: 0.2% chance of exploitation in the next 30 days.

Inappropriate user token revocation due to a logic error in the token revocation endpoint implementation in Cloudfoundry UAA v77.30.0 to v78.7.0 and in Cloudfoundry Deployment v48.7.0 to v54.10.0.

Affected products

  • Cloudfoundry Cf-Deployment: after 48.7.0, up to and including 54.11.0
  • Cloudfoundry Uaa-Release: from 77.30.0, before 78.8.0 (fixed in 78.8.0)

Published 2026-03-05. Last modified 2026-06-17.