AUGUST 24, 2026
Live Feed
Back to database
Case File

CVE-2026-47826

CRITICAL · CVSS 9.1 EPSS 0.34%

Source: NVD + CISA KEV + EPSS · Published 2026-07-09 · Last synced 2026-08-08

CyberRota Analysis

AI-Generated

The BOSH CLI tool is vulnerable to a path traversal flaw in the blobs.yml file, enabling attackers to write arbitrary files and potentially exfiltrate sensitive data. This critical vulnerability, with a CVSS score of 9.1, poses a significant risk to organizations using affected versions prior to v7.10.4. Security teams should prioritize patching this vulnerability to mitigate the risk of unauthorized data access and system compromise.

CVE
CVE-2026-47826
Severity
CRITICAL
CVSS
9.1
EPSS
0.34%

Original NVD Description

The blobs.yml path key traversal vulnerability in the BOSH CLI tool allows an attacker to write arbitrary files and exfiltrate sensitive information. Affected versions: BOSH CLI tool versions prior to v7.10.4.

Related CVEs

Other vulnerabilities affecting the same vendor(s)