Cloud Foundry Logo
blog single gear
Security Advisory

CVE-2026-41861 – Arbitrary Root File Write via Path Traversal in BOSH agent

Severity

Low

CVSSv4: Low 2.3 (CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N)

CVSSv3: Medium 4.2 (CVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L)

Vendor

CloudFoundry Foundation

Versions Affected

*Severity is Medium unless otherwise noted.

BOSH
– All bosh agent versions < v2.847.0 (jammy <= v1.1202, or noble <= v1.364)

Description

Path Traversal in BOSH-Ecosystem / BOSH allows an IaaS-metadata attacker to make the agent write a root-owned file with partially attacker-controlled body to any path ending in .network, and create any missing parent directories with mode 0777 via network Alias on Ubuntu.

The vulnerability is due to the way the bosh-agent handles network configuration files. The interfaceConfigurationFile function constructs file paths using user-supplied input without proper validation, allowing for directory traversal.

Mitigation

Users of affected products are strongly encouraged to follow the mitigations below.

The Cloud Foundry project recommends upgrading the following releases:

BOSH-Ecosystem / BOSH
– Upgrade the BOSH agent to version to v2.847.0 or greater

Credit

This issue was responsibly reported by VMware Tanzu by Broadcom.

History

Aug 6th: Initial vulnerability report published.

Cloud Foundry Foundation Security Team Profile Image

Cloud Foundry Foundation Security Team, AUTHOR

SEE ALL ARTICLES