Every CVE whose affected-product data names Cloudfoundry Bosh Cli, ordered by CVSS severity, with EPSS exploit prediction and CISA KEV status.
CVEs (4)
CVE-2026-47826 — CVSS 9.1 (critical): The blobs.yml path key traversal vulnerability in the BOSH CLI tool allows an attacker to write arbitrary files and exfiltrate sensitive…
CVE-2026-47828 — CVSS 8.8 (high): During bosh create-env and bosh delete-env, the CLI uploads compiled CPI packages and rendered job templates to the new VM's DAV blobstore…
CVE-2026-41857 — CVSS 7.8 (high): A compromised or malicious BOSH Director can execute arbitrary shell commands on the operator's workstation when the operator runs bosh ssh…
CVE-2026-47829 — CVSS 7.8 (high): Argument Injection in bosh-cli allows a compromised BOSH Director to inject arbitrary OpenSSH options into the locally-spawned ssh process…