Command Injection in BOSH CLI tool on windows in Cloud Foundry allows a remote attacker to execute arbitrary shell commands via command injection… (CVE-2026-47827)
CVE-2026-47827 is a command injection vulnerability in the BOSH CLI tool on Windows within Cloud Foundry environments. This flaw allows a remote attacker to execute arbitrary shell commands due to insufficient input validation or sanitization. The vulnerability has a high severity rating with a CVSS score of 7.5, indicating significant potential impact on confidentiality, integrity, and availability. No specific affected versions or patch information is provided in the available data.
AI Analysis
Technical Summary
The BOSH CLI tool on Windows platforms in Cloud Foundry contains a command injection vulnerability that permits remote attackers to execute arbitrary shell commands. This vulnerability arises from improper handling of input that leads to command injection. The CVSS 3.1 base score is 7.5 (AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H), reflecting a high-severity remote attack vector with high impact on system confidentiality, integrity, and availability. No known exploits are reported in the wild, and no patch or remediation details are currently available.
Potential Impact
Successful exploitation allows a remote attacker to execute arbitrary shell commands on the affected system, potentially leading to full compromise of the system's confidentiality, integrity, and availability. This can result in unauthorized data access, modification, or disruption of services.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, restrict access to the BOSH CLI tool on Windows and monitor for suspicious activity related to command execution. Avoid exposing the CLI tool to untrusted networks or users.
Command Injection in BOSH CLI tool on windows in Cloud Foundry allows a remote attacker to execute arbitrary shell commands via command injection… (CVE-2026-47827)
Description
CVE-2026-47827 is a command injection vulnerability in the BOSH CLI tool on Windows within Cloud Foundry environments. This flaw allows a remote attacker to execute arbitrary shell commands due to insufficient input validation or sanitization. The vulnerability has a high severity rating with a CVSS score of 7.5, indicating significant potential impact on confidentiality, integrity, and availability. No specific affected versions or patch information is provided in the available data.
CVSS v3.1
Score 7.5high
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The BOSH CLI tool on Windows platforms in Cloud Foundry contains a command injection vulnerability that permits remote attackers to execute arbitrary shell commands. This vulnerability arises from improper handling of input that leads to command injection. The CVSS 3.1 base score is 7.5 (AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H), reflecting a high-severity remote attack vector with high impact on system confidentiality, integrity, and availability. No known exploits are reported in the wild, and no patch or remediation details are currently available.
Potential Impact
Successful exploitation allows a remote attacker to execute arbitrary shell commands on the affected system, potentially leading to full compromise of the system's confidentiality, integrity, and availability. This can result in unauthorized data access, modification, or disruption of services.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, restrict access to the BOSH CLI tool on Windows and monitor for suspicious activity related to command execution. Avoid exposing the CLI tool to untrusted networks or users.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-p279-35hc-hx5p
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-47827"]
- Ecosystems
- []
- Database Specific Severity
- HIGH
- Cvss Version
- 3.1
Threat ID: 6a885f17acd9273b493f788d
Added to database: 08/21/2026, 14:22:15 UTC
Last enriched: 08/21/2026, 14:26:52 UTC
Last updated: 08/22/2026, 03:51:58 UTC
Views: 4
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.