CVE-2026-47830: CWE-732 Incorrect Permission Assignment for Critical Resource in Cloud Foundry Foundation bosh-windows-stemcell-builder
Incorrect Permission Assignment in BOSH.Utils.psm1 in BOSH-Ecosystem bosh-windows-stemcell-builder allows low-privilege authenticated users to overwrite C:\bosh\service_wrapper.exe or C:\bosh\bosh-agent.exe and gain NT AUTHORITY\SYSTEM on the next service restart or reboot. This can lead to full host control. Affected versions: bosh-windows-stemcell-builder versions prior to v2019.98.
AI Analysis
Technical Summary
This vulnerability (CVE-2026-47830) arises from improper permission settings in the BOSH.Utils.psm1 component of the bosh-windows-stemcell-builder. It permits authenticated users with low privileges to overwrite key service executables located at C:\bosh\service_wrapper.exe or C:\bosh\bosh-agent.exe. Upon the next service restart or system reboot, the attacker can escalate privileges to NT AUTHORITY\SYSTEM, effectively gaining full control over the host system. The issue affects all versions of bosh-windows-stemcell-builder prior to v2019.98. No official patch or remediation level has been published yet, and there are no known exploits in the wild.
Potential Impact
Exploitation allows low-privilege authenticated users to achieve full system control by overwriting critical service executables and gaining NT AUTHORITY\SYSTEM privileges after a service restart or reboot. This can lead to complete compromise of the affected host.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, restrict low-privilege user access to the affected system and monitor for unauthorized modifications to C:\bosh\service_wrapper.exe and C:\bosh\bosh-agent.exe. Consider applying additional access controls or workarounds as recommended by the vendor once available.
CVE-2026-47830: CWE-732 Incorrect Permission Assignment for Critical Resource in Cloud Foundry Foundation bosh-windows-stemcell-builder
Description
Incorrect Permission Assignment in BOSH.Utils.psm1 in BOSH-Ecosystem bosh-windows-stemcell-builder allows low-privilege authenticated users to overwrite C:\bosh\service_wrapper.exe or C:\bosh\bosh-agent.exe and gain NT AUTHORITY\SYSTEM on the next service restart or reboot. This can lead to full host control. Affected versions: bosh-windows-stemcell-builder versions prior to v2019.98.
CVSS v4.0
Score 8.5high
Affected software
pkg:github/cloudfoundry/bosh-windows-stemcell-builderRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability (CVE-2026-47830) arises from improper permission settings in the BOSH.Utils.psm1 component of the bosh-windows-stemcell-builder. It permits authenticated users with low privileges to overwrite key service executables located at C:\bosh\service_wrapper.exe or C:\bosh\bosh-agent.exe. Upon the next service restart or system reboot, the attacker can escalate privileges to NT AUTHORITY\SYSTEM, effectively gaining full control over the host system. The issue affects all versions of bosh-windows-stemcell-builder prior to v2019.98. No official patch or remediation level has been published yet, and there are no known exploits in the wild.
Potential Impact
Exploitation allows low-privilege authenticated users to achieve full system control by overwriting critical service executables and gaining NT AUTHORITY\SYSTEM privileges after a service restart or reboot. This can lead to complete compromise of the affected host.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, restrict low-privilege user access to the affected system and monitor for unauthorized modifications to C:\bosh\service_wrapper.exe and C:\bosh\bosh-agent.exe. Consider applying additional access controls or workarounds as recommended by the vendor once available.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- vmware
- Date Reserved
- 2026-05-20T10:00:48.931Z
- Cvss Version
- 4.0
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a4f46b8c9d9e3dbe3ae73ea
Added to database: 07/09/2026, 06:59:04 UTC
Last enriched: 07/16/2026, 10:18:46 UTC
Last updated: 08/22/2026, 22:52:14 UTC
Views: 124
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.