All findings

CVE-2026-40965, CVE-2026-41005 critical

Cloud Foundry UAA credits Claude-assisted reports for two authentication CVEs

Cloud Foundry UAA advisories credit Ada Logics in collaboration with Claude and Anthropic Research for a critical EC private-key exposure and a SAML encrypted-assertion authentication bypass.

Bug class
Authentication bypass and key disclosure
Affected codebase
Cloud Foundry UAA
Credited system
Claude / Anthropic Research
Disclosed
June 11, 2026
Attribution
Direct source attribution
Severity
critical
Source status: Cloud Foundry's May 14 and June 11, 2026 advisories directly credit Arthur Chan from Ada Logics in collaboration with Claude and Anthropic Research. CVE-2026-40965 is rated critical at CVSS 10.0; CVE-2026-41005 is rated critical at CVSS 9.0/9.5 depending on CVSS version.

Summary

Cloud Foundry published two UAA advisories with direct Claude collaboration credits. CVE-2026-40965 exposed EC private-key components through the public /token_keys endpoint when deployments used EC keys for JWT signing.

CVE-2026-41005 allowed UAA to treat SAML encryption as a substitute for IdP signatures in two SAML flows, accepting unsigned encrypted assertions or responses under affected configurations.

Attribution

Both advisories credit Arthur Chan from Ada Logics in collaboration with Claude and Anthropic Research. The vulnerabilities were accepted by Cloud Foundry and fixed through UAA and CF Deployment release upgrades.


References


Catalogued in the Bugflation public ledger. Disagree with the attribution or severity label? Email the desk.