CVE-2026-41857EPSS p12.1%
CVE-2026-41857CVE-2026-41857
cloudfoundry / bosh_cli
Description
A compromised or malicious BOSH Director can execute arbitrary shell commands on the operator's workstation when the operator runs bosh ssh (or bosh scp/bosh logs -f) with default flags.
Affected versions: BOSH CLI versions prior to 7.10.5.
Scoring
| CVSS | 7.8 () |
| Vector | CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
| EPSS | 0.23% probability of exploitation · percentile 12.1% · 2026-10-05T12:00:23Z |
| Last modified | 2026-07-13 |