Traffic Interception Vulnerability in BOSH Director vCenter CPI
CVE-2026-41012
7.7HIGH
What is CVE-2026-41012?
A traffic interception vulnerability exists in the BOSH Director vCenter CPI, enabling an attacker positioned between the BOSH Director and vCenter to impersonate the vCenter REST API. This allows for the capture of administrator credentials through HTTP Basic authentication during CPI calls. Due to inadequate authentication security in the communication protocol, attackers can exploit the lack of proper certificate validation and pinning, leading to complete control over the virtualization infrastructure. Consequently, the successful impersonation can compromise all VMs, datastores, and networks managed by the vulnerable vCenter instance, affecting potentially hundreds or thousands of resources.
Affected Version(s)
bosh-vsphere-cpi-release 0 < 98.0.6
