Severity
HIGH
CVSSv4: High 7.7 (CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N)
CVSSv3: High 7.5 (CVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H)
Vendor
CloudFoundry Foundation
Versions Affected
*Severity is HIGH unless otherwise noted.
BOSH CLI tool
– All versions < v2.840.0
Description
Command Injection in BOSH CLI tool on windows in Cloud Foundry allows a remote attacker to execute arbitrary shell commands via command injection vulnerabilities.
Mitigation
Users of affected products are strongly encouraged to follow the mitigations below.
The Cloud Foundry project recommends upgrading the following releases:
BOSH CLI tool
– Upgrade BOSH CLI tool versions to v2.840.0 or greater
Credit
This issue was responsibly reported by VMware Tanzu by Broadcom.
History
Initial vulnerability report published Aug 20th 2026
