Junglewise Threat Intelligence

CVE-2026-41012: Cloud Foundry BOSH VSphere CPI certificate validation bypass

CVE-2026-41012 · Severity: high · CVSS 7.7 · Published 2026-08-29

Vendors: Cloud Foundry Foundation.

Executive brief

BOSH Director is infrastructure-as-code software that manages virtual machine deployment across vCenter environments. A weakness in how it validates secure connections to vCenter allows attackers on the network to intercept communications and steal vCenter administrator credentials, leading to complete control of all virtual machines, storage, and networks managed by that instance.

Technical details

The vulnerability is an improper certificate validation flaw in BOSH VSphere CPI's communication with vCenter REST API. Although HTTPS is used, insufficient certificate validation and lack of certificate pinning allow attackers positioned on the network path between BOSH Director and vCenter to perform man-in-the-middle (MITM) attacks. Attackers can impersonate the vCenter API endpoint and capture HTTP Basic authentication credentials (username/password) transmitted in every CPI call. Since vCenter credentials grant administrative access to the entire virtualization infrastructure, successful exploitation enables complete takeover of all managed VMs, datastores, and networks. Affected versions are BOSH VSphere CPI prior to v98.0.6; patches have been made available.

Affected products

  • Cloud Foundry Foundation BOSH VSphere CPI All versions prior to v98.0.6

Timeline

  • 2026-08-27: advisory: Security advisory published by Cloud Foundry Foundation
  • 2026-08-29: other: CVE-2026-41012 published

References