BotBeat
...
← Back

> ▌

CloudflareCloudflare
RESEARCHCloudflare2026-04-08

Security Researcher Demonstrates Chain of Self-XSS and CSRF Vulnerabilities in Cloudflare Access

Key Takeaways

  • ▸Three individually low-severity vulnerabilities (Self-XSS, Cookie Tossing, CSRF token weakness) can be chained into a critical bypass of Cloudflare Access approval mechanisms
  • ▸The attack demonstrates how 'informative' triaged bugs can become significant security issues when combined in creative ways
  • ▸Both the CF_Authorization cookie and CSRF token protections can be simultaneously undermined through the vulnerability chain
Source:
Hacker Newshttps://kazama.in/self-xss-to-cloudflare-single-click-approvals/↗

Summary

A security researcher has documented a sophisticated vulnerability chain affecting Cloudflare Access's Temporary Auth approval mechanism. The attack combines three individually low-severity bugs—a Self-XSS on the SAML SSO endpoint, cookie tossing vulnerability on the *.cloudflareaccess.com domain, and a predictable CSRF token—to achieve a single-click bypass of the access request approval flow. The vulnerabilities were reported through HackerOne to Cloudflare's security team.

The attack exploits the authentication and CSRF protection mechanisms that guard Cloudflare's Temporary Auth feature, which enforces approval-based access to protected applications. By chaining the three bugs together, an attacker can forge unauthorized access approvals without legitimate authorization. The researcher notes that after an initial fix was deployed, a second Self-XSS variant was discovered in Cloudflare's Browser Isolation feature, allowing the entire attack chain to be replayed, demonstrating the systemic nature of the vulnerability class.

  • A second variant in Browser Isolation suggests broader validation issues across Cloudflare's security infrastructure

Editorial Opinion

This disclosure highlights a critical lesson in vulnerability assessment: individually dismissing bugs as 'informative' or 'self-XSS' can obscure systemic security weaknesses when those bugs are carefully combined. The researcher's persistence in finding a chain after the initial fix—and discovering a second variant—suggests that organizations need to adopt more holistic security reviews that consider how low-impact vulnerabilities might interact. This case demonstrates why comprehensive security audits matter as much as individual bug fixes.

CybersecurityEthics & BiasAI Safety & Alignment

More from Cloudflare

CloudflareCloudflare
FUNDING & BUSINESS

Cloudflare Lays Off 20% of Workforce, CEO Blames AI Obsolescence for Middle Management Roles

2026-05-22
CloudflareCloudflare
RESEARCH

Cloudflare's Ask AI Feature Silently Creates Permanent API Tokens With Broad Read Access

2026-05-21
CloudflareCloudflare
UPDATE

Cloudflare Rebuilds Browser Run on Containers for 4x Better Performance and Scale

2026-05-14

Comments

Suggested

AnthropicAnthropic
INDUSTRY REPORT

Anthropic's Mythos AI Model Sparks Regulatory Scrutiny Over Cybersecurity Implications

2026-05-25
OpenAIOpenAI
INDUSTRY REPORT

Press Gazette Launches AI Scandal Tracker as Major News Outlets Struggle with AI Governance

2026-05-24
AnthropicAnthropic
PRODUCT LAUNCH

Anthropic Prepares Mythos 1 for Public Release via Claude Code and Claude Security

2026-05-24
← Back to news
© 2026 BotBeat
AboutPrivacy PolicyTerms of ServiceContact Us