CVE-2026-41860

HIGH

Cloud Foundry Foundation Bosh < 282.1.9 - Inadequate Encryption Strength

Title source: rule
STIX 2.1

Description

CWE-326 in BOSH allows a local attacker to steal Basic-auth credentials or redirect UAA token requests via MITM. HttpRequestHelper#create_async_endpoint and #send_http_get_request_synchronous hard-code OpenSSL::SSL::VERIFY_NONE, enabling an attacker to intercept traffic between bosh-monitor and the BOSH director or UAA and steal credentials. Affected versions: - BOSH: all versions prior to v282.1.9 (inclusive); fixed in v282.1.9 or later

Scores

CVSS v3 8.8
EPSS 0.0008
EPSS Percentile 0.1%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-326
Status published
Products (1)
Cloud Foundry Foundation/BOSH < 282.1.9
Published Jun 04, 2026
Tracked Since Jun 04, 2026