CVE-2026-41012

7.7

Cloud Foundry · bosh-vsphere-cpi-release

A traffic interception vulnerability in the BOSH Director vCenter CPI allows unauthenticated attackers to capture administrator credentials via improper certificate validation.

Executive summary

A critical traffic interception vulnerability in the Cloud Foundry BOSH Director vCenter CPI allows attackers to capture administrative credentials, leading to total virtualization infrastructure takeover.

Vulnerability

The vulnerability is caused by improper certificate validation (CWE-295) during communication between the BOSH Director and vCenter, which permits unauthenticated attackers positioned in the network path to impersonate the vCenter REST API. This flaw enables the interception of HTTP Basic authentication credentials during routine cloud infrastructure operations.

Business impact

The compromise of vCenter administrative credentials grants an attacker full control over the entire virtualized estate, including all virtual machines, datastores, and network configurations. Given the CVSS score of 7.7, this high-severity vulnerability poses an existential risk to business continuity, as it allows for the unauthorized modification, destruction, or exfiltration of the entire cloud environment.

Remediation

Immediate Action: Upgrade the Cloud Foundry bosh-vsphere-cpi-release to version 98.0.6 or later to implement proper certificate validation.

Proactive Monitoring: Monitor network traffic between the BOSH Director and the vCenter management interface for unauthorized interception attempts or unexpected man-in-the-middle connections.

Compensating Controls: Ensure that all management traffic is strictly isolated within a secure, dedicated management VLAN and enforce strict network access control lists to prevent unauthorized devices from positioning themselves between the BOSH Director and vCenter.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

The severity of this credential exposure requires immediate attention from infrastructure and security teams. Because the vulnerability facilitates a full takeover of the virtualized environment, organizations must prioritize the deployment of the 98.0.6 patch across all affected BOSH Director instances to eliminate the risk of credential interception.

More Cloud Foundry CVEs

Sources

Originally found and disclosed by Tanzu at Broadcom (responsible disclosure), per the CVE Program record.