Security Advisory

CVE-2026-47826

9.1
CRITICAL

Vulnerability Description

The blobs.yml path key traversal vulnerability in the BOSH CLI tool allows an attacker to write arbitrary files and exfiltrate sensitive information. Affected versions: BOSH CLI tool versions prior to v7.10.4.
Published Date July 9, 2026
Official Source NIST NVD Advisory