PT-2026-46133 · Bosh · Bosh
CVE-2026-41859
·
Published
2026-06-04
·
Updated
2026-07-22
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
BOSH versions prior to 282.1.9
Description
A network man-in-the-middle between nats-sync and the BOSH director can steal director credentials, such as the Basic auth header or UAA client secret, and tamper with the VM list written into the NATS authorization file. Stolen credentials provide administrative director access. This occurs because the
bosh api response body() function in UsersSync builds a Net::HTTP client with verify mode set to OpenSSL::SSL::VERIFY NONE for director calls to the endpoints "/info", "/deployments", and "/deployments//vms".Recommendations
Update to version 282.1.9 or later.
Fix
Improper Certificate Validation
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Bosh