CVE-2026-47826Disclosed(cloudfoundry / bosh_cli)

LOWCVSS 9.1 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch cloudfoundry bosh_cli systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

The blobs.yml path key traversal vulnerability in the BOSH CLI tool allows an attacker to write arbitrary files and exfiltrate sensitive information. Affected versions: BOSH CLI tool versions prior to v7.10.4.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • bosh_cli

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 2 signals
  • Disclosed: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-07-09); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Products
bosh_cli

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-07-09: 1Mentions · 2026-08-06: 1Patch / Workaround · 2026-07-09: 1Patch / Workaround · 2026-08-06: 1Technical Details · 2026-07-09: 1Technical Details · 2026-08-06: 107-0908-06
Signal classification2 categories
Disclosed
150.0%
Patch
150.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-07-091
Disclosed1
2026-08-061
Patch1
Full discourse2 posts
  • takenaka hiroya@Joe_Biden_ja
    Patch

    BOSH CLI の blobs.yml にパス走査。リリースを展開しただけで作業ディレクトリの外に書き込まれます。CVSS 9.1、修正版は v7.10.4。危ないのは開発者の端末より、人が見ていないCIのランナーのほうです。まずどこで自動実行されているかを洗い出してください。 https://cve.autoarticles.net/cve/CVE-2026-47826

    Post summary

    The post alerts about CVE‑2026‑47826, a path‑traversal flaw in BOSH CLI with a CVSS score of 9.1, and notes that patch version v7.10.4 is available. It urges users to identify where automatic execution may occur, emphasizing the need to apply the fix.

    0000059
    561 followersView on X
  • Hugo | DevOps | Cybersecurity 🇱🇻@HugoValters
    Disclosed

    #CVE-2026-47826 - Path Traversal in #BOSH #CLI allows arbitrary file write & data exfil. #CVSS 8.8. No patch available yet. Mitigate immediately. #CVEAlert #infosec #devsecops #devops #cybersecurity #git #github #gitlab #developers https://www.valtersit.com/cve/CVE-2026-47826/

    Post summary

    CVE-2026-47826 is a disclosed path traversal vulnerability in BOSH CLI that enables arbitrary file writes and data exfiltration, with no patch yet available and an immediate mitigation recommendation.

    0000082
    974 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appcloudfoundrybosh_cli---

Explore more