Security Advisory

CVE-2026-41857

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-07-09 04:31:33
Last updated 2026-07-09 14:12:24
Assigner vmware
CVSS score 7.8
State PUBLISHED

Description

A compromised or malicious BOSH Director can execute arbitrary shell commands on the operator's workstation when the operator runs bosh ssh (or bosh scp/bosh logs -f) with default flags. Affected versions: BOSH CLI versions prior to 7.10.5.