PT-2026-68725 · Unknown · Bosh Agent

CVE-2026-41861

·

Published

2026-08-06

·

Updated

2026-08-07

CVSS v3.1

4.2

Medium

VectorAV:A/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L
Name of the Vulnerable Software and Affected Versions BOSH agent versions prior to 2.847.0
Description A path traversal issue exists where an IaaS-metadata attacker can force the agent to write a root-owned file to any path ending in .network. This process allows the creation of any missing parent directories with mode 0777 via the network Alias on Ubuntu. The attacker can partially control the body of the written file.
Recommendations Update BOSH agent to version 2.847.0 or later.

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-41861

Affected Products

Bosh Agent