CVE-2026-41861

Severity CVSS v4.0:
Pending analysis
Type:
CWE-22 Path Traversal
Publication date:
06/08/2026
Last modified:
18/08/2026

Description

Path Traversal in BOSH-Ecosystem / BOSH allows an IaaS-metadata attacker to make the agent write a root-owned file with partially attacker-controlled body to any path ending in .network, and create any missing parent directories with mode 0777 via network Alias on Ubuntu.<br /> <br /> <br /> <br /> Affected versions: BOSH agent