PT-2026-56696 · Bosh Cli · Bosh Cli

CVE-2026-41857

·

Published

2026-07-09

·

Updated

2026-07-09

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions BOSH CLI versions prior to 7.10.5
Description A compromised or malicious BOSH Director can execute arbitrary shell commands on the operator's workstation. This occurs when the operator uses the bosh ssh, bosh scp, or bosh logs -f commands with default flags.
Recommendations Update BOSH CLI to version 7.10.5 or later.

Exploit

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-41857

Affected Products

Bosh Cli