AUGUST 24, 2026
Live Feed
Back to database
Case File

CVE-2026-41857

HIGH · CVSS 7.8 EPSS 0.15%

Source: NVD + CISA KEV + EPSS · Published 2026-07-09 · Last synced 2026-08-08

CyberRota Analysis

AI-Generated

A vulnerability exists in BOSH CLI versions prior to 7.10.5, allowing a compromised BOSH Director to execute arbitrary shell commands on an operator's workstation when using commands like bosh ssh, bosh scp, or bosh logs -f with default flags. This poses a significant risk as it could lead to unauthorized access and control over the operator's environment. Organizations utilizing BOSH CLI for deployment and management should prioritize upgrading to mitigate potential exploitation.

CVE
CVE-2026-41857
Severity
HIGH
CVSS
7.8
EPSS
0.15%

Original NVD Description

A compromised or malicious BOSH Director can execute arbitrary shell commands on the operator's workstation when the operator runs bosh ssh (or bosh scp/bosh logs -f) with default flags. Affected versions: BOSH CLI versions prior to 7.10.5.

Related CVEs

Other vulnerabilities affecting the same vendor(s)