CVE-2026-47839EPSS p22.1%
CVE-2026-47839CVE-2026-47839
Description
A vulnerability allows users authenticating through a federated OIDC provider to obtain the uaa.admin scope despite operators restricting that provider through externalGroupsWhitelist configuration. The issue occurs specifically when an OIDC identity provider uses groupMappingMode: AS_SCOPES with a wildcard externalGroupsWhitelist entry.
Scoring
| EPSS | 0.31% probability of exploitation · percentile 22.1% · 2026-10-05T12:00:23Z |
| Last modified | 2026-09-18 |