VYPR
Critical severity9.1NVD Advisory· Published Jul 9, 2026· Updated Jul 13, 2026

CVE-2026-47826

CVE-2026-47826

Description

The blobs.yml path key traversal vulnerability in the BOSH CLI tool allows an attacker to write arbitrary files and exfiltrate sensitive information. Affected versions: BOSH CLI tool versions prior to v7.10.4.

Affected products

2
  • cpe:2.3:a:cloudfoundry:bosh_cli:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:cloudfoundry:bosh_cli:*:*:*:*:*:*:*:*range: <7.10.4
    • (no CPE)range: <v7.10.4

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.