Threats Tagged 'cve-2026-59335'
View all threats tagged with 'cve-2026-59335'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2026-59335'
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-59335 is a high-severity vulnerability in Cloud Foundry UAA affecting deployments backed by MySQL with default collation. It arises from improper handling of case sensitivity in the identity zone authorization check, allowing a remote authenticated attacker with zones.write authority to bypass restrictions by using non-lowercase zone identifiers. This leads to unauthorized access to the privileged system identity zone, enabling the attacker to overwrite the system zone's JWT signing key, forge admin JWTs, and fully compromise UAA and dependent Cloud Foundry deployments. PostgreSQL and HSQLDB backends are not affected. Join the discussion | GCVE Database | 08/25/2026, 11:05:11 UTC Added: 08/25/2026, 13:38:11 UTC |
CVE-2026-59335 is a high-severity vulnerability in Cloud Foundry UAA affecting deployments backed by MySQL with default collation. It involves improper handling of case sensitivity in the identity zone authorization check, allowing a remote authenticated attacker with zones.write authority to bypass restrictions by using non-lowercase zone identifiers. This leads to unauthorized access to the privileged system identity zone, enabling the attacker to overwrite the system zone's JWT signing key and forge tokens with admin privileges, fully compromising UAA and dependent Cloud Foundry deployments. PostgreSQL and HSQLDB backends are not affected. Join the discussion | CVE Database V5 | 08/25/2026, 11:05:11 UTC Added: 08/25/2026, 11:22:53 UTC |
Showing 1 to 2 of 2 results