Privilege Escalation Vulnerability in BPM Managed Jobs by Cloud Foundry
CVE-2026-47833
6.8MEDIUM
What is CVE-2026-47833?
The vulnerability allows a compromised process within a BPM container to perform a symlink attack that can escalate privileges to the host system. By exploiting this issue, an attacker can change the ownership of critical system files, including /etc/shadow, thereby gaining access to sensitive password hashes stored on the host. This poses a significant risk to the confidentiality of credentials for all jobs managed by BPM, making it crucial for users to enforce version updates to v1.4.30 or later to mitigate the threats associated with this vulnerability.
Affected Version(s)
bpm-release 0 < 1.4.30
