CVE-2026-41861: CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in CloudFoundry Foundation BOSH
Path Traversal in BOSH-Ecosystem / BOSH allows an IaaS-metadata attacker to make the agent write a root-owned file with partially attacker-controlled body to any path ending in .network, and create any missing parent directories with mode 0777 via network Alias on Ubuntu. Affected versions: BOSH agent < v2.847.0 (jammy <= v1.1202, or noble <= v1.364). Lower bound unspecified in advisory ("All bosh agent versions").
AI Analysis
Technical Summary
This vulnerability in the BOSH ecosystem involves a path traversal flaw (CWE-22) that enables an attacker with access to IaaS metadata to manipulate the BOSH agent into writing files owned by root to arbitrary locations ending with .network. The attacker can also cause the creation of parent directories with overly permissive permissions (0777) via network alias functionality on Ubuntu. The affected versions include all BOSH agent versions before 2.847.0, specifically jammy versions up to 1.1202 and noble versions up to 1.364. The vulnerability has a CVSS 3.1 base score of 4.2, reflecting moderate impact with attack vector requiring adjacent network access and high attack complexity.
Potential Impact
An attacker able to control IaaS metadata can exploit this vulnerability to write files as root to arbitrary paths ending in .network, potentially enabling partial control over system configuration or behavior. The creation of directories with mode 0777 could further weaken system security by allowing broad access. However, the CVSS score and vector indicate that exploitation requires high complexity and access to the adjacent network, limiting the ease of attack. There is no indication of confidentiality impact, but integrity and availability impacts are low to moderate.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. No official patch or fix link is provided in the available data. Users should monitor vendor communications for updates and consider restricting access to IaaS metadata services to trusted entities to reduce exposure. Since this is not a cloud service, remediation responsibility lies with the user deploying BOSH agents.
CVE-2026-41861: CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in CloudFoundry Foundation BOSH
Description
Path Traversal in BOSH-Ecosystem / BOSH allows an IaaS-metadata attacker to make the agent write a root-owned file with partially attacker-controlled body to any path ending in .network, and create any missing parent directories with mode 0777 via network Alias on Ubuntu. Affected versions: BOSH agent < v2.847.0 (jammy <= v1.1202, or noble <= v1.364). Lower bound unspecified in advisory ("All bosh agent versions").
CVSS v3.1
Score 4.2medium
Affected software
pkg:github/cloudfoundry/bosh-agentRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability in the BOSH ecosystem involves a path traversal flaw (CWE-22) that enables an attacker with access to IaaS metadata to manipulate the BOSH agent into writing files owned by root to arbitrary locations ending with .network. The attacker can also cause the creation of parent directories with overly permissive permissions (0777) via network alias functionality on Ubuntu. The affected versions include all BOSH agent versions before 2.847.0, specifically jammy versions up to 1.1202 and noble versions up to 1.364. The vulnerability has a CVSS 3.1 base score of 4.2, reflecting moderate impact with attack vector requiring adjacent network access and high attack complexity.
Potential Impact
An attacker able to control IaaS metadata can exploit this vulnerability to write files as root to arbitrary paths ending in .network, potentially enabling partial control over system configuration or behavior. The creation of directories with mode 0777 could further weaken system security by allowing broad access. However, the CVSS score and vector indicate that exploitation requires high complexity and access to the adjacent network, limiting the ease of attack. There is no indication of confidentiality impact, but integrity and availability impacts are low to moderate.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. No official patch or fix link is provided in the available data. Users should monitor vendor communications for updates and consider restricting access to IaaS metadata services to trusted entities to reduce exposure. Since this is not a cloud service, remediation responsibility lies with the user deploying BOSH agents.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-hr6c-84vf-jf53
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-41861"]
- Ecosystems
- []
- Database Specific Severity
- MODERATE
- Cvss Version
- 3.1
Threat ID: 6a7573a0bf8831d539d9203a
Added to database: 08/07/2026, 05:56:48 UTC
Last enriched: 08/07/2026, 08:47:26 UTC
Last updated: 08/08/2026, 03:40:59 UTC
Views: 2
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.