Answer in brief
CVE-2026-47840 records a High severity (CVSS 7.5) vulnerability in LDAP StartTLS unconditionally disables hostname verification. The current sources do not mark it as known exploited. The current feed maps CloudFoundry Foundation/Cf-deployment (generic), CloudFoundry Foundation/UAA (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 7.5. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps CloudFoundry Foundation/Cf-deployment (generic), CloudFoundry Foundation/UAA (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| CloudFoundry Foundation/Cf-deploymentgeneric | >=0 <56.2.0 | 56.2.0 |
| CloudFoundry Foundation/UAAgeneric | >=0 <78.13.0 | 78.13.0 |
Published upstream
Jul 9, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Jul 9, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Jul 9, 2026
A network attacker positioned between UAA and its LDAP directory can impersonate the directory using any certificate from any trusted CA, then harvest the LDAP bind password and every end-user password sent during simple-bind authentication, and return forged group memberships that grant themselves admin scopes. This affects every deployment that authenticates users against LDAP over StartTLS. Affected versions: UAA versions prior to v78.13.0; Cf-deployment versions prior to v56.2.0.
Quoted source text, attributed separately from HOL analysis.
Answer in brief
CVE-2026-47840 records a High severity (CVSS 7.5) vulnerability in LDAP StartTLS unconditionally disables hostname verification. The current sources do not mark it as known exploited. The current feed maps CloudFoundry Foundation/Cf-deployment (generic), CloudFoundry Foundation/UAA (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 7.5. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps CloudFoundry Foundation/Cf-deployment (generic), CloudFoundry Foundation/UAA (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| CloudFoundry Foundation/Cf-deploymentgeneric | >=0 <56.2.0 | 56.2.0 |
| CloudFoundry Foundation/UAAgeneric | >=0 <78.13.0 | 78.13.0 |
Published upstream
Jul 9, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Jul 9, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Jul 9, 2026
A network attacker positioned between UAA and its LDAP directory can impersonate the directory using any certificate from any trusted CA, then harvest the LDAP bind password and every end-user password sent during simple-bind authentication, and return forged group memberships that grant themselves admin scopes. This affects every deployment that authenticates users against LDAP over StartTLS. Affected versions: UAA versions prior to v78.13.0; Cf-deployment versions prior to v56.2.0.
Quoted source text, attributed separately from HOL analysis.