AUGUST 24, 2026
Live Feed
Back to database
Case File

CVE-2026-47830

HIGH · CVSS 8.8 EPSS 0.10%

Source: NVD + CISA KEV + EPSS · Published 2026-07-09 · Last synced 2026-08-08

CyberRota Analysis

AI-Generated

A vulnerability exists in the BOSH-Ecosystem bosh-windows-stemcell-builder, where low-privilege authenticated users can exploit incorrect permission assignments to overwrite critical executables, specifically C:\bosh\service_wrapper.exe and C:\bosh\bosh-agent.exe. This flaw allows attackers to escalate their privileges to NT AUTHORITY\SYSTEM upon the next service restart or system reboot, potentially granting them full control over the host. Organizations utilizing affected versions prior to v2019.98 should prioritize remediation to mitigate the risk of unauthorized access and system compromise.

CVE
CVE-2026-47830
Severity
HIGH
CVSS
8.8
EPSS
0.10%
Windows

Original NVD Description

Incorrect Permission Assignment in BOSH.Utils.psm1 in BOSH-Ecosystem bosh-windows-stemcell-builder allows low-privilege authenticated users to overwrite C:\bosh\service_wrapper.exe or C:\bosh\bosh-agent.exe and gain NT AUTHORITY\SYSTEM on the next service restart or reboot. This can lead to full host control. Affected versions: bosh-windows-stemcell-builder versions prior to v2019.98.