CVE-2024-38806
Failure to properly synchronize user's permissions in UAA in Cloud Foundry Foundation v40.17.0 https://github.com/cloudfoundry/cf-deployment/releases/tag/v40.17.0 , potentially resulting in users retaining access rights they should not have. This can allow them to perform operations beyond their intended permissions.
Scoring
- Severity
- LOW
- CVSS base score
- 3.9
- CVSS vector
- CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:L
- EPSS probability
- 0.13%
- CWE
- CWE-440
- Published
- 2024-07-18
- Last modified
- 2026-03-13
Affected products
- n/a UAA
Weakness type
Related vulnerabilities
- CVE-2026-16769 — RS9116W/SiWx917 plaintext pause encryption request causes DOS
- CVE-2026-65934 — BT122 plaintext pause encryption request causes DOS
- CVE-2026-65932 — BT122 stops advertising
- CVE-2026-8806 — Denial-of-service (DoS) vulnerability in MELSEC iQ-F Series FX5-ENET/IP Ethernet module
- CVE-2026-42752 — WordPress Stripe Payments plugin <= 2.0.98 - Bypass Vulnerability vulnerability
- CVE-2026-49316 — Indian Scout Bobber 2025 WCM CAN bus-off attack silently bypasses anti-theft shutdown
- CVE-2026-42534 — Jostle logic bypass degrades resolution performance
- CVE-2026-41136 — free5GC AMF missing default case in Content-Type switch in HTTPUEContextTransfer