Junglewise Threat Intelligence

CVE-2026-47827: Cloud Foundry BOSH CLI command injection on Windows

CVE-2026-47827 · Severity: high · CVSS 7.5 · Published 2026-08-21

Vendors: Cloud Foundry Foundation.

Executive brief

BOSH CLI is a command-line tool used by Cloud Foundry operators to manage cloud infrastructure and deploy applications. A command injection vulnerability on Windows allows a remote attacker to execute arbitrary shell commands, potentially gaining control over the deployment platform and compromising the applications and data it hosts.

Technical details

A command injection vulnerability exists in the BOSH CLI tool's Windows implementation, likely in PowerShell command execution or argument handling. The vulnerability allows an unauthenticated remote attacker to inject arbitrary shell commands via specially crafted input, with the attack requiring adjacent network access and specific timing conditions. Successful exploitation leads to arbitrary command execution with the privileges of the BOSH CLI process, potentially enabling full infrastructure compromise. The issue affects all versions prior to v2.840.0; users should upgrade immediately.

Affected products

  • Cloud Foundry Foundation BOSH CLI before v2.840.0

Timeline

  • 2026-08-20: disclosed

References