Privilege Escalation Vulnerability in BPM Managed Jobs by Cloud Foundry
CVE-2026-47833

6.8MEDIUM

Key Information:

Vendor
CVE Published:
18 June 2026

What is CVE-2026-47833?

The vulnerability allows a compromised process within a BPM container to perform a symlink attack that can escalate privileges to the host system. By exploiting this issue, an attacker can change the ownership of critical system files, including /etc/shadow, thereby gaining access to sensitive password hashes stored on the host. This poses a significant risk to the confidentiality of credentials for all jobs managed by BPM, making it crucial for users to enforce version updates to v1.4.30 or later to mitigate the threats associated with this vulnerability.

Affected Version(s)

bpm-release 0 < 1.4.30

References

CVSS V4

Score:
6.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
Low
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.