CVE-2026-47827 PUBLISHED

CVE-2026-47827 – BOSH CLI Powershell Injection

Assigner: vmware
Reserved: 20.05.2026 Published: 21.08.2026 Updated: 21.08.2026

Command Injection in BOSH CLI tool on windows in Cloud Foundry allows a remote attacker to execute arbitrary shell commands via command injection vulnerabilities

Metrics

CVSS Vector: CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS Score: 7.5

Product Status

Vendor Cloud Foundry Foundation
Product BOSH CLI
Versions Default: affected
  • affected from 0.0 to 2.840.0 (excl.)

References