PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-47829 CloudFoundry Foundation CVE debrief

CVE-2026-47829 is an Argument Injection vulnerability in bosh-cli. A compromised BOSH Director can inject arbitrary OpenSSH options into the locally-spawned ssh process when an operator runs certain non-interactive SSH commands, leading to local command execution on the operator's workstation. This issue affects bosh-cli versions prior to v7.10.4. The vulnerability allows for the execution of arbitrary commands on the operator's local machine, potentially leading to privilege escalation or lateral movement within the environment. Operators and administrators should be aware of this vulnerability and take steps to mitigate it.

Vendor
CloudFoundry Foundation
Product
bosh-cli
CVSS
HIGH 7.7
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-09
Original CVE updated
2026-07-13
Advisory published
2026-07-09
Advisory updated
2026-07-13

Who should care

Operators and administrators using bosh-cli, especially those with BOSH Directors that may be compromised, should be aware of this vulnerability and take steps to mitigate it. This includes ensuring that BOSH Directors are properly secured and monitored for potential compromise, using secure SSH configurations, and restricting access to BOSH Directors. Additionally, operators should monitor for suspicious activity on their workstations.

Technical summary

The vulnerability exists in the bosh-cli tool, which is used to interact with BOSH Directors. When an operator runs certain non-interactive SSH commands, such as 'bosh ssh -c' or 'bosh logs -f', the compromised BOSH Director can inject arbitrary OpenSSH options. This injection can lead to local command execution on the operator's workstation. The issue is particularly severe because it allows for the execution of arbitrary commands on the operator's local machine, potentially leading to privilege escalation or lateral movement within the environment.

Defensive priority

High

Recommended defensive actions

  • Upgrade bosh-cli to version 7.10.4 or later
  • Ensure that BOSH Directors are properly secured and monitored for potential compromise
  • Use secure SSH configurations and restrict access to BOSH Directors
  • Monitor for suspicious activity on operator workstations
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented

Evidence notes

The CVE record was published on 2026-07-09T07:16:24.150Z and was last modified on 2026-07-13T13:33:49.180Z. The NVD entry is currently Analyzed. This information is based on the provided source corpus. Further verification is recommended to ensure accuracy.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-47829 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-47829

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-47829 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-47829

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://www.cloudfoundry.org/blog/cve-2026-47829-argument-injection-in-bosh-cli-allows-local-command-execution-on-operator-workstations-via-compromised-director/

    [email protected] - Vendor Advisory

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.