PatchSiren cyber security CVE debrief
CVE-2026-47827 Cloud Foundry Foundation CVE debrief
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-21T10:16:38.647Z and has not been modified since then. The vulnerability is a command injection vulnerability in the BOSH CLI tool on Windows in Cloud Foundry, allowing remote attackers to execute arbitrary shell commands. The vulnerability has a CVSS score of 7.5 and is classified as HIGH severity. Organizations using Cloud Foundry and the BOSH CLI tool on Windows should be aware of this vulnerability and take necessary actions to prevent exploitation. This includes verifying BOSH CLI tool installations, reviewing and updating Cloud Foundry configurations, and monitoring for suspicious activity related to the BOSH CLI tool. Security teams and vulnerability management teams should also be aware of this vulnerability and provide guidance on mitigation and remediation efforts. Evidence is limited, and further verification is needed.
- Vendor
- Cloud Foundry Foundation
- Product
- BOSH CLI
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-21
- Original CVE updated
- 2026-08-22
- Advisory published
- 2026-08-21
- Advisory updated
- 2026-08-22
Who should care
Organizations using Cloud Foundry and the BOSH CLI tool on Windows should be aware of this vulnerability and take necessary actions to prevent exploitation. This includes verifying BOSH CLI tool installations, reviewing and updating Cloud Foundry configurations, and monitoring for suspicious activity related to the BOSH CLI tool. Security teams and vulnerability management teams should also be aware of this vulnerability and provide guidance on mitigation and remediation efforts.
Technical summary
A command injection vulnerability exists in the BOSH CLI tool on Windows in Cloud Foundry, allowing remote attackers to execute arbitrary shell commands. The vulnerability has a CVSS score of 7.5 and is classified as HIGH severity. This vulnerability affects organizations using Cloud Foundry and the BOSH CLI tool on Windows. Organizations should prioritize verifying their BOSH CLI tool installations and ensure they are updated to a secure version.
Defensive priority
Organizations using Cloud Foundry should prioritize verifying their BOSH CLI tool installations and ensure they are updated to a secure version.
Recommended defensive actions
- Verify BOSH CLI tool installations and ensure they are updated to a secure version
- Review and update Cloud Foundry configurations to prevent exploitation
- Monitor for suspicious activity related to the BOSH CLI tool
Evidence notes
The CVE record indicates a command injection vulnerability in the BOSH CLI tool on Windows in Cloud Foundry, allowing remote attackers to execute arbitrary shell commands. Evidence is limited, and further verification is needed. Organizations should verify their BOSH CLI tool installations and review Cloud Foundry configurations to prevent exploitation. The vulnerability has a CVSS score of 7.5 and is classified as HIGH severity.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-47827 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-47827
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-47827 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-47827
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://www.cloudfoundry.org/blog/cve-2026-47827-bosh-cli-powershell-injection/
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.