CVE-2026-47826

cloudfoundry bosh_cli: Sicherheitsluecke

criticalEPSS 0.5%

Affected

  • cloudfoundry/bosh_cli lt *..7.10.4

Description

The blobs.yml path key traversal vulnerability in the BOSH CLI tool allows an attacker to write arbitrary files and exfiltrate sensitive information. Affected versions: BOSH CLI tool versions prior to v7.10.4.

Affected products

The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.

cloudfoundrybosh_cli
7.10.4fixed from 7.10.4

Metrics

9.1
Source: nvd-v3
44.0 %
High — this CVE ranks above the median of all CVEs scored today (rank ≥ 36%).
Show all metrics
Severity
critical
no public PoC known
0.5 %
Low — model estimates < 1% exploitation likelihood.
Published
2026-07-09 07:16 UTC

References & sources

Linked advisories