VDB

CVE-2026-22727

CVE-2026-22727 PUBLISHED CVSS 7.5 HIGH

Unprotected internal endpoints in Cloud Foundry Capi Release 1.226.0 and below, and CF Deployment v54.9.0 and below on all platforms allows any user who has bypassed the firewall to potentially replace droplets and therefore applications allowing them to access secure application information.

EPSS 0.20% · 9.9th percentile

Risk Scores

CVSS 3.1
7.5
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
0.20%
9.9th percentile

Affected Products

VendorProductVersions
CloudfoundryCloud Foundry1.0, 1.0, 1.0

Timeline

  • Mar 17, 2026 CVE Published
  • Mar 17, 2026 PoC Published
  • Mar 18, 2026 EPSS Score
  • Mar 19, 2026 EPSS Score
  • Mar 19, 2026 CVE Updated
  • Mar 20, 2026 EPSS Score
  • Mar 21, 2026 EPSS Score
  • Mar 22, 2026 EPSS Score
  • Mar 23, 2026 EPSS Score
  • Mar 24, 2026 EPSS Score
  • Mar 25, 2026 EPSS Score
  • Mar 29, 2026 Security Advisory
Open in Interactive Console →
$ Console Community · 100/wk Open console ›