Traffic Interception Vulnerability in BOSH Director vCenter CPI
CVE-2026-41012

7.7HIGH

Key Information:

Vendor
CVE Published:
29 August 2026

What is CVE-2026-41012?

A traffic interception vulnerability exists in the BOSH Director vCenter CPI, enabling an attacker positioned between the BOSH Director and vCenter to impersonate the vCenter REST API. This allows for the capture of administrator credentials through HTTP Basic authentication during CPI calls. Due to inadequate authentication security in the communication protocol, attackers can exploit the lack of proper certificate validation and pinning, leading to complete control over the virtualization infrastructure. Consequently, the successful impersonation can compromise all VMs, datastores, and networks managed by the vulnerable vCenter instance, affecting potentially hundreds or thousands of resources.

Affected Version(s)

bosh-vsphere-cpi-release 0 < 98.0.6

References

CVSS V3.1

Score:
7.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Tanzu at Broadcom (responsible disclosure)
.