PT-2026-68725 · Unknown · Bosh Agent
CVE-2026-41861
·
Published
2026-08-06
·
Updated
2026-08-07
CVSS v3.1
4.2
Medium
| Vector | AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
BOSH agent versions prior to 2.847.0
Description
A path traversal issue exists where an IaaS-metadata attacker can force the agent to write a root-owned file to any path ending in .network. This process allows the creation of any missing parent directories with mode 0777 via the network Alias on Ubuntu. The attacker can partially control the body of the written file.
Recommendations
Update BOSH agent to version 2.847.0 or later.
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Bosh Agent