CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2026-47826

Critical · CVSS 9.1

BOSH CLI — Path Traversal (CWE-22) - arbitrary file write and sensitive information exfiltration via blobs.yml path key

CVSS
9.1
nvd
EPSS
0.33%
25th pct
KEV
No
Class
other
CWE-22

Description

The blobs.yml path key traversal vulnerability in the BOSH CLI tool allows an attacker to write arbitrary files and exfiltrate sensitive information. Affected versions: BOSH CLI tool versions prior to v7.10.4.

Search profile — drives PoC discovery

Symbols blobs.ymlpath keyblobs.yamlblob path traversal../AddBlobGetBlobblobsConfigBlobsConfigblob_pathblobs config path
Keywords CVE-2026-47826BOSH CLIblobs.yml path traversalBOSH blob path key traversalBOSH CLI arbitrary file writeBOSH CLI v7.10.4CloudFoundry BOSH path traversalblobs yaml traversal exploitBOSH CLI PoC
Versions: < v7.10.4

References

Status: enriched · ingested 2026-07-13T18:00:21.000Z · profiled 2026-07-13T18:30:21.000Z