CVE-2026-47829: Argument Injection in BOSH CLI Allows Local Command Execution on Operator Workstations via Compromised Director
Argument Injection in bosh-cli allows a compromised BOSH Director to inject arbitrary OpenSSH options into the locally-spawned ssh process when an operator runs bosh ssh -c, bosh logs -f, or other non-interactive SSH paths, leading to local command execution on the operator's workstation. Affected versions: bosh-cli versions prior to v7.10.4.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
bosh-clito a version that resolves this vulnerability.Fixed in v7.10.4 - Compensating control
Avoid running bosh ssh -c and other non-interactive SSH paths in bosh-cli on operator workstations until bosh-cli is upgraded to v7.10.4.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-47829?
The severity of CVE-2026-47829 is rated high with a score of 8.3.
How do I fix CVE-2026-47829?
To fix CVE-2026-47829, ensure that your bosh-cli is updated to the latest version that addresses this vulnerability.
What type of attack does CVE-2026-47829 facilitate?
CVE-2026-47829 facilitates local command execution through argument injection in bosh-cli.
Who is affected by CVE-2026-47829?
Operators using bosh-cli who connect to a compromised BOSH Director are affected by CVE-2026-47829.
What is the impact of CVE-2026-47829?
The impact of CVE-2026-47829 includes unauthorized local command execution on operator workstations, potentially leading to system compromise.