CVE-2026-41861
Severity CVSS v4.0:
Pending analysis
Type:
CWE-22
Path Traversal
Publication date:
06/08/2026
Last modified:
18/08/2026
Description
Path Traversal in BOSH-Ecosystem / BOSH allows an IaaS-metadata attacker to make the agent write a root-owned file with partially attacker-controlled body to any path ending in .network, and create any missing parent directories with mode 0777 via network Alias on Ubuntu.<br />
<br />
<br />
<br />
Affected versions: BOSH agent
Impact
Base Score 3.x
4.20
Severity 3.x
MEDIUM


