Description
Command Injection in BOSH CLI tool on windows in Cloud Foundry allows a remote attacker to execute arbitrary shell commands via command injection vulnerabilities
Published: 2026-08-21
Score: 7.5 High
EPSS: 1.2% Low
KEV: No
Impact: Remote Command Execution
Action: Immediate Patch
AI Analysis

Impact

The BOSH CLI tool on Windows contains a command injection flaw that allows attackers to execute arbitrary PowerShell commands. Inferred from the nature of the vulnerability, an attacker could run any commands with the privileges of the user running the CLI, potentially compromising confidentiality, integrity, and availability of the affected system.

Affected Systems

The issue impacts the BOSH CLI distributed by the Cloud Foundry Foundation for Windows platforms. No specific version information is provided, so all unpatched Windows builds of the CLI may be vulnerable.

Risk and Exploitability

The CVSS base score of 7.5 indicates high severity. EPSS data shows a 2% likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is inferred to be remote, since the CLI is often invoked by processes that can supply command arguments. Successful exploitation would grant the attacker full execution rights on the host running the CLI.

Generated by OpenCVE AI on August 21, 2026 at 19:44 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Download and install the latest patched version of BOSH CLI from the Cloud Foundry Foundation website
  • Restrict file system permissions on the BOSH CLI executable and its configuration directories to only authorized administrators
  • Apply the principle of least privilege to any accounts that invoke BOSH CLI, limiting them to the minimum necessary rights

Generated by OpenCVE AI on August 21, 2026 at 19:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 18:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-78

Fri, 21 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-77
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 21 Aug 2026 15:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-78

Fri, 21 Aug 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Cloudfoundry
Cloudfoundry bosh Cli
Vendors & Products Cloudfoundry
Cloudfoundry bosh Cli

Fri, 21 Aug 2026 09:45:00 +0000

Type Values Removed Values Added
Description Command Injection in BOSH CLI tool on windows in Cloud Foundry allows a remote attacker to execute arbitrary shell commands via command injection vulnerabilities
Title CVE-2026-47827 – BOSH CLI Powershell Injection
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Cloudfoundry Bosh Cli
cve-icon MITRE

Status: PUBLISHED

Assigner: vmware

Published:

Updated: 2026-08-22T03:56:21.999Z

Reserved: 2026-05-20T10:00:48.931Z

Link: CVE-2026-47827

cve-icon Vulnrichment

Updated: 2026-08-21T16:01:18.196Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-21T10:16:38.647

Modified: 2026-08-28T18:47:30.163

Link: CVE-2026-47827

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T19:45:03Z

Weaknesses
  • CWE-77

    Improper Neutralization of Special Elements used in a Command ('Command Injection')