GSSA-2026-09-HREC4XGHSA-7mh4-g74q-c7q8September 14, 2026Cloud broker issues and replaces application credentials without authentication
The application registration endpoint on the cloud broker verified no credential before issuing one. A caller naming an existing application instance received a valid credential for it, and the stored credential was replaced. Rotation did not remediate the issue.
Affected (1)
- GPlatformgplatform-control
All versions affected.
Mitigations
Workarounds
- Treat deployment and application instance identifiers as sensitive until the fix is applied, and restrict who can read application configuration and the list of deployed applications. This reduces exposure without closing the issue.
- Where a network control is available, restrict access to the cloud broker's registration endpoint to the hosting environment itself.
- Monitor for unexpected credential rotation. A legitimate application rotates its credential only when it restarts, so a rotation with no corresponding restart indicates exploitation.
Solutions
- Update to a build in which registration requires the application's existing credential whenever the application instance is already known.
- The same update rejects an application instance identifier that belongs to a different deployment, and rejects an application identifier the deployment does not host.
- The client SDK was updated in the same change to present the credential the platform already provisions to each application, so no action is required from application authors beyond taking the updated SDK.
Exploits
- An unauthenticated request to the registration endpoint naming an existing application instance returns a valid credential for that instance and replaces the stored one.
Configurations
- Affects deployments serving cloud-hosted applications. Self-hosted installations are not affected.
- Exploitation requires knowledge of two identifiers that name a deployment and an application instance. Neither is a credential, and both are available to anyone able to read an application's own configuration or an organisation's list of applications.
- No authentication is otherwise required, and no user interaction is involved.
Overview
The application registration endpoint on the cloud broker did not verify any credential before issuing one. A caller naming an application instance that already existed received a newly minted application token in the response, and the credential stored for that instance was replaced with it.
Rotating the credential did not remediate the issue, because the endpoint would mint another for the next caller.
Self-hosted installations are not affected. There, the equivalent endpoint is reachable only from the operator's own network, which is the boundary the design relies on; the cloud surface had no such boundary.
Severity
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H- Attack vector
- Network
- Attack complexity
- High
- Privileges required
- None
- User interaction
- None
- Scope
- Changed
- Confidentiality
- High
- Integrity
- High
- Availability
- High
Weaknesses (3)
Context
Impacts
Application instance takeover. An unauthenticated caller obtains a valid application credential and can then read that application's operator-managed settings, reach its billing surface and obtain a signed entitlement lease.
CAPEC-115Denial of service against the legitimate application. Issuing a new credential replaces the stored one, so the running application can no longer authenticate. Repeating the request keeps it offline, which causes it to lose its entitlement lease and refuse licensed functionality.
CAPEC-603Cross-deployment impact. An application instance identifier belonging to one deployment could be registered from another, replacing the credential and manifest held for it.
CAPEC-115Unauthorised application instances. A registration could attach an application the deployment does not host, creating records against the affected organisation and consuming its licensed capacity.
CAPEC-233
Timeline
- 09/14/2026 00:00
Identified during an internal security review of GPlatform Control.
- 09/14/2026 00:30
Confirmed by analysis. No exploitation was performed against any running deployment, and there is no indication of exploitation in the wild.
- 09/14/2026 01:00
Reported to the vendor. Vendor and reporter are the same party, so no external coordination applies.
- 09/14/2026 02:00
Remediation began.
- 09/14/2026 04:40
Fixed in the product. Registration now requires the application's existing credential, and rejects identifiers that do not belong to the deployment making the request. The client SDK was updated in the same change to present the credential the platform provisions. Regression tests cover each refusal.