Description
A compromised or malicious BOSH Director can execute arbitrary shell commands on the operator's workstation when the operator runs bosh ssh (or bosh scp/bosh logs -f) with default flags.
Affected versions: BOSH CLI versions prior to 7.10.5.
Published: 2026-07-09
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A malicious or compromised BOSH Director can inject arbitrary shell commands into an operator’s workstation when the operator runs commands such as bosh ssh, bosh scp, or bosh logs –f with the default flags. This injection flaw (CWE‑78) allows a remote adversary to execute any local command on the operator’s machine, compromising confidentiality, integrity, and availability.

Affected Systems

CloudFoundry BOSH CLI versions prior to 7.10.5 are vulnerable. Operators using any of those versions to interact with a BOSH Director—regardless of network configuration—are at risk.

Risk and Exploitability

The vulnerability is remote; exploitation requires a compromised BOSH Director and the operator to invoke the CLI with default flags. Once injected commands are processed, arbitrary local execution occurs. The CVSS score of 7.1 signals moderate‑to‑high severity, while the EPSS score of <1% indicates a low but non‑zero likelihood of exploitation. The issue is not listed in CISA KEV.

Generated by OpenCVE AI on July 26, 2026 at 16:02 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the BOSH CLI to version 7.10.5 or later, which removes the default shell injection flaw.
  • If an immediate upgrade is not possible, avoid using the CLI’s default flags for commands such as bosh ssh, bosh scp, or bosh logs –f; explicitly limit command execution or use secure connection options.
  • Enforce BOSH Director access controls so that only trusted users or organizations can issue commands from the CLI.

Generated by OpenCVE AI on July 26, 2026 at 16:02 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 26 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-78

Thu, 23 Jul 2026 10:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-78

Tue, 21 Jul 2026 01:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-78

Thu, 16 Jul 2026 10:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-78

Tue, 14 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-78

Mon, 13 Jul 2026 01:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-78

Fri, 10 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-78

Fri, 10 Jul 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Cloudfoundry
Cloudfoundry bosh Cli
Vendors & Products Cloudfoundry
Cloudfoundry bosh Cli

Thu, 09 Jul 2026 23:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-78

Thu, 09 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 09 Jul 2026 05:30:00 +0000

Type Values Removed Values Added
Description A compromised or malicious BOSH Director can execute arbitrary shell commands on the operator's workstation when the operator runs bosh ssh (or bosh scp/bosh logs -f) with default flags. Affected versions: BOSH CLI versions prior to 7.10.5.
Title BOSH CLI Shell Injection
References
Metrics cvssV3_0

{'score': 7.8, 'vector': 'CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Cloudfoundry Bosh Cli
cve-icon MITRE

Status: PUBLISHED

Assigner: vmware

Published:

Updated: 2026-07-09T14:12:24.049Z

Reserved: 2026-04-22T06:22:10.081Z

Link: CVE-2026-41857

cve-icon Vulnrichment

Updated: 2026-07-09T14:11:44.307Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-26T16:15:17Z

Weaknesses

No weakness.