Cloud Foundry disclosed CVE-2026-40965, a high-severity vulnerability in UAA that can expose Elliptic Curve private key material through the public /token_keys JSON endpoint. The endpoint is meant to publish public keys for JWT verification, but affected deployments using EC keys for token signing could inadvertently return private key components, creating a risk of token forgery and broader compromise of authentication trust. The issue is tracked under CWE-200 and carries a CVSS v3.1 vector of AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L.
The flaw affects Cloud Foundry UAA versions v76.12.0 through v78.12.0 and CF Deployment versions v30.0.0 through v56.0.0. Cloud Foundry said the issue does not affect RSA-based configurations, and fixes are available in uaa_release v78.13.0 and CF Deployment v56.1.0 or later. A separate Cloud Foundry advisory also disclosed CVE-2026-40964, involving unauthorized read access to CF logs, indicating multiple security issues were addressed in the platform during the same disclosure period.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
Cloud Foundry maintainers advised users affected by CVE-2026-40965 to upgrade UAA to v78.13.0 or later and deployments using global configuration templates to v56.1.0 or later. The guidance accompanied reporting that the flaw exposed EC private keys via the public /token_keys endpoint.
Cloud Foundry published an advisory for CVE-2026-40964 concerning unauthorized read access to Cloud Foundry logs. The reference identifies this as a separate vulnerability disclosure event.
Cloud Foundry published an advisory for CVE-2026-40965 describing that the public /token_keys endpoint could expose EC private key material in UAA deployments using Elliptic Curve keys for JWT signing.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
securityonline.info
Open sourcecvefeed.io
Open sourcecloudfoundry.org
Open sourcecloudfoundry.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.