{"id":"CVE-2026-47839","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-47839","summary":"A vulnerability allows users authenticating through a federated OIDC provider to obtain the uaa.admin scope despite operators restricting that provider through externalGroupsWhitelist…","details":"A vulnerability allows users authenticating through a federated OIDC provider to obtain the uaa.admin scope despite operators restricting that provider through externalGroupsWhitelist configuration. The issue occurs specifically when an OIDC identity provider uses groupMappingMode: AS_SCOPES with a wildcard externalGroupsWhitelist entry.","published":"2026-09-11T10:16:51.567","modified":"2026-09-11T10:16:51.567","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[],"fix":null,"references":[{"type":"WEB","url":"https://www.cloudfoundry.org/blog/cve-2026-47839-federated-oidc-users-can-bypass-externalgroupswhitelist-to-gain-uaa-admin/"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-09-11T10:16:51.567"}}