PT-2026-45615 · Unknown+1 · Cf-Auth-Proxy+2

CVE-2026-40964

·

Published

2026-06-01

·

Updated

2026-07-22

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions log-cache release versions prior to v3.2.7 CF Deployment versions prior to v55.?.0
Description An authentication bypass in cf-auth-proxy allows an unauthenticated remote attacker to gain read access to all logs and metrics for every application and platform component. This is achieved by minting a JSON Web Token (JWT), a compact and self-contained way for securely transmitting information between parties as a JSON object, which the cf-auth-proxy accepts as a valid logs.admin token.
Recommendations Update log-cache release to v3.2.7 or later. Update CF Deployment to v55.?.0 or later.

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-40964

Affected Products

Cf-Deployment
Cf-Auth-Proxy
Log-Cache