AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-41861

MEDIUM · CVSS 4.2 EPSS 0.15%

Source: NVD + CISA KEV + EPSS · Published 2026-08-06 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

A path traversal vulnerability in the BOSH agent on Ubuntu allows an attacker with IaaS-metadata access to create a root-owned file at any path ending in .network, potentially leading to unauthorized file manipulation and privilege escalation. This issue affects BOSH agent versions prior to v2.847.0, including specific versions of Jammy and Noble. Organizations using affected versions should prioritize patching to mitigate potential exploitation risks.

CVE
CVE-2026-41861
Severity
MEDIUM
CVSS
4.2
EPSS
0.15%
Ubuntu

Original NVD Description

Path Traversal in BOSH-Ecosystem / BOSH allows an IaaS-metadata attacker to make the agent write a root-owned file with partially attacker-controlled body to any path ending in .network, and create any missing parent directories with mode 0777 via network Alias on Ubuntu. Affected versions: BOSH agent < v2.847.0 (jammy <= v1.1202, or noble <= v1.364). Lower bound unspecified in advisory ("All bosh agent versions").