CVE-2026-47826: blobs.yaml Path Traversal Allows File Writes
Published Jul 9, 2026
·Updated
The blobs.yml path key traversal vulnerability in the BOSH CLI tool allows an attacker to write arbitrary files and exfiltrate sensitive information. Affected versions: BOSH CLI tool versions prior to v7.10.4.
Affected Software
2 affected components
BOSH BOSH CLI<7.10.4
Cloudfoundry Bosh Cli<7.10.4
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
BOSH CLI toolto a version that resolves this vulnerability.Fixed in v7.10.4
Event History
Jul 9, 2026
CVE Published
via MITRE·05:45 AM
Data Sourced
via MITRE·05:45 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:16 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-47826?
The severity of CVE-2026-47826 is rated as high with a score of 8.8.
2
How do I fix CVE-2026-47826?
To fix CVE-2026-47826, upgrade to BOSH CLI tool version 7.10.4 or later.
3
What type of vulnerability is CVE-2026-47826?
CVE-2026-47826 is a path traversal vulnerability that allows file writes.
4
What can an attacker do with CVE-2026-47826?
An attacker can exploit CVE-2026-47826 to write arbitrary files and potentially exfiltrate sensitive information.
5
Which versions of BOSH CLI are affected by CVE-2026-47826?
BOSH CLI tool versions prior to 7.10.4 are affected by CVE-2026-47826.