Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2026-59358 — Proof-of-concept lab and exploit client for CVE-2026-59358, demonstrating Cloud Foundry UAA reuse of a user PKCE token as client_credentials Bearer to mint privileged client tokens. | Kitploit
Tools/GitHubGitHub/abraxas/cve-2026-59358
Vulnerability AnalysisExploitationWeb Application ExploitationPenetration TestingIdentity & Access Management (IAM)AuthenticationLabs & Practice
GitHubabraxas/cve-2026-59358

CVE-2026-59358

Proof-of-concept lab and exploit client for CVE-2026-59358, demonstrating Cloud Foundry UAA reuse of a user PKCE token as client_credentials Bearer to mint privileged client tokens.

View Repository
19h 18m agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

Abraxas Labs - CVE-2026-59358

abraxaslabs.tech  ·  github.com/abraxas  ·  @abraxas_null  ·  [email protected]  ·  CVE-2026-59358

CVE-2026-59358

Class: Privilege leftover Reach: Remote

Cloud Foundry UAA v79.6.0 - VMware by Broadcom / Cloud Foundry Foundation

I am @abraxas_null. Loopback lab. The client is CVE-2026-59358-Abraxas-Labs.py.

A public PKCE user access token is accepted as Bearer client authentication on grant_type=client_credentials for the same dual-grant client. UAA mints a client-only token with that client's authorities (clients.write in this lab). The user token itself 403s on POST /oauth/clients. The leftover token creates a new OAuth client. Independent lab of the published CVE. Credit: Minseong Kim (mak3bread).

CVECVE-2026-59358 · CVE.org
ClassPrivilege leftover (user token reused as client_credentials Bearer; not RCE)
ReachRemote (attacker's own user access token)
CWECWE-287
CVSSHigh: 7.6 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
ProductCloud Foundry UAA
AffectedUAA v3.7.0 through v79.6.0; cf-deployment through v60.4.0
PatchedUAA v79.7.0; cf-deployment v60.5.0
Authauthenticated (attacker's own user PKCE token)
LicenseGNU Affero GPL v3.0
Lab127.0.0.1 only

What an attacker can do

Log in through a public OAuth client that also lists client_credentials. Replay that user JWT as Authorization: Bearer on POST /oauth/token with grant_type=client_credentials. UAA returns a client-only token with the client's authorities. If those include clients.write, create new OAuth clients with attacker-chosen authorities. No client secret required.

The user token cannot administer clients by itself. The leftover is the token-endpoint check treating any valid access token whose client_id matches as client authentication.

Impact scales with that client's authorities. The combo (public user flow plus client_credentials on one client_id) is not default.


How I found it

Cloud Foundry published CVE-2026-59358 on 5 Oct 2026. I pinned last-affected cfidentity/uaa:v79.6.0, stood up a dedicated dual-grant public client labpub, and walked PKCE as the stock user marissa. Negative control: user token on POST /oauth/clients is 403. Attack: same Bearer on client_credentials is 200, then 201 creating labwit-CVE-2026-59358-WITNESS.

Wrong turns already recorded: pinning v79.7.0 (patched); hitting /oauth/token without the /uaa context path; mixing localhost and 127.0.0.1 in issuer and redirect; using the stock login client (no clients.write); password grant instead of PKCE; sending Basic client_id:secret plus the user Bearer (that is legitimate client auth).


The lab

HTTP 18258 on loopback. Image docker.io/cfidentity/uaa:v79.6.0 (linux/amd64). Compose project cve-2026-59358. ./run.sh.

  • lab/docker-compose.yml
  • lab/uaa.yml
  • lab/run.sh
  • lab/poc.py

Target only 127.0.0.1:18258 (or the loopback you bound).

python3 CVE-2026-59358-Abraxas-Labs.py

That chdirs into lab/ and runs run.sh (compose up, wait for /uaa/info, then poc.py).

Witness: minted client_credentials JWT carries clients.write and POST /oauth/clients returns 201 for labwit-CVE-2026-59358-WITNESS. User token on the same endpoint is 403.

SUCCESS CVE-2026-59358 grant=client_credentials clients.write create-http=201 id=labwit-CVE-2026-59358-WITNESS CVE-2026-59358-WITNESS

Ways to lose without learning anything:

  • image v79.7.0 or later
  • reverse shell
  • RCE payload

The fix

Upgrade UAA to v79.7.0 or newer, or cf-deployment to v60.5.0. Until then, do not put a public user-facing grant and client_credentials on the same client_id, and keep clients.write on dedicated non-public clients.

Re-run CVE-2026-59358-Abraxas-Labs.py against the patched build: the user Bearer on client_credentials must stay non-200.


References

  • CVE-2026-59358 · CVE.org

  • CVE-2026-59358 · NVD

  • Cloud Foundry advisory

  • github.com/cloudfoundry/uaa

  • hub.docker.com/r/cfidentity/uaa tag v79.6.0

  • Abraxas Labs: abraxaslabs.tech · github.com/abraxas · @abraxas_null · [email protected]


License

GNU Affero GPL v3.0. See LICENSE.


The client talks to loopback. Using it against systems you do not own is not authorized by Abraxas Labs. No warranty.

abraxaslabs.tech · github.com/abraxas · @abraxas_null · [email protected]

Download Tool