PT-2026-45615 · Unknown+1 · Cf-Auth-Proxy+2
CVE-2026-40964
·
Published
2026-06-01
·
Updated
2026-07-22
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
log-cache release versions prior to v3.2.7
CF Deployment versions prior to v55.?.0
Description
An authentication bypass in cf-auth-proxy allows an unauthenticated remote attacker to gain read access to all logs and metrics for every application and platform component. This is achieved by minting a JSON Web Token (JWT), a compact and self-contained way for securely transmitting information between parties as a JSON object, which the cf-auth-proxy accepts as a valid
logs.admin token.Recommendations
Update log-cache release to v3.2.7 or later.
Update CF Deployment to v55.?.0 or later.
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cf-Deployment
Cf-Auth-Proxy
Log-Cache