Skip to content
COOEY

EXPOSURES › CVE-2026-47826

CVE-2026-47826

CRITICAL
DETAIL
SourceNVD · cve Published2026-07-09 CVSS9.1 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2026-47826 ↗
SHAME 45/100 unpatcheddata-breach

CloudFoundry's BOSH CLI tool allows attackers to write arbitrary files and exfiltrate sensitive data via path traversal in blobs.yml before v7.10.4.

This critical vulnerability enables attackers to write arbitrary files and exfiltrate sensitive information through path traversal in the BOSH CLI tool, posing a significant risk to FedRAMP vendors and DIB organizations relying on CloudFoundry infrastructure. Organizations must immediately patch to version 7.10.4 or later to prevent potential data loss and compliance violations.

Shame score — A critical path traversal vulnerability in a widely-used infrastructure tool that allows arbitrary file writing and exfiltration, though not actively exploited or ransomware-linked.

▸ RECOMMENDED ACTION  Critical severity — schedule patching of the affected products.

DESCRIPTION

The blobs.yml path key traversal vulnerability in the BOSH CLI tool allows an attacker to write arbitrary files and exfiltrate sensitive information. Affected versions: BOSH CLI tool versions prior to v7.10.4.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.