Home

Description

Unprotected internal endpoints in Cloud Foundry Capi Release 1.226.0 and below, and CF Deployment v54.9.0 and below on all platforms allows any user who has bypassed the firewall to potentially replace droplets and therefore applications allowing them to access secure application information.

PUBLISHED Reserved 2026-01-09 | Published 2026-03-17 | Updated 2026-03-19 | Assigner vmware




HIGH: 7.5CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Problem types

CWE-306

Product status

Default status
unaffected

1.0 (git)
affected

References

www.cloudfoundry.org/...22727-unprotected-internal-endpoints

cve.org (CVE-2026-22727)

nvd.nist.gov (CVE-2026-22727)

Download JSON