CVE-2026-41012
Received Received - Intake

Traffic Interception in BOSH Director vCenter CPI

Vulnerability report for CVE-2026-41012, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-29

Last updated on: 2026-08-29

Assigner: VMware

Description

Traffic interception vulnerability in BOSH Director vCenter CPI allows attackers positioned between BOSH Director and vCenter to impersonate vCenter REST API and capture administrator credentials via HTTP Basic auth, leading to complete virtualization infrastructure takeover. An attacker who can intercept traffic between the BOSH Director and vCenter can establish a malicious server impersonating the vCenter REST API. When the BOSH Director makes CPI calls to perform routine cloud infrastructure operations, the attacker captures the vCenter administrator username and password transmitted via HTTP Basic authentication. The vulnerability stems from insufficient authentication security in the communication protocol between BOSH Director and vCenter. While HTTPS may be used, the lack of proper certificate validation and pinning allows attackers to successfully impersonate vCenter endpoints. Because vCenter credentials typically grant full administrative control over the entire virtualization estate, successful credential capture yields complete takeover of every VM, datastore, and network the CPI manages. This exposure exists on every CPI call (including routine deployment operations, not just when tags are configured) and cannot be mitigated by supplying a CA certificate alone. The attack impacts all infrastructure managed by the compromised vCenter instance, potentially affecting hundreds or thousands of VMs across multiple deployments and environments.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-29
Last Modified
2026-08-29
Generated
2026-08-29
AI Q&A
2026-08-29
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
vmware bosh_vsphere_cpi to 98.0.6 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-295 The product does not validate, or incorrectly validates, a certificate.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability allows attackers between BOSH Director and vCenter to impersonate the vCenter REST API and capture administrator credentials via HTTP Basic auth during routine operations. It stems from insufficient certificate validation in their communication protocol.

Detection Guidance

Monitor network traffic between BOSH Director and vCenter for unusual HTTP Basic auth requests or unexpected certificate validation failures. Inspect logs for CPI calls showing vCenter REST API impersonation attempts or credential transmission without proper HTTPS validation.

Impact Analysis

An attacker could gain full administrative control over your virtualization infrastructure, including all VMs, datastores, and networks managed by the compromised vCenter. This could lead to complete infrastructure takeover.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data and systems, potentially violating GDPR's data protection requirements and HIPAA's security rules for protected health information. Compromised vCenter credentials may allow attackers to access or manipulate regulated data, leading to compliance breaches.

Mitigation Strategies

Upgrade BOSH VSphere CPI to version v98.0.6 or later immediately. Ensure proper certificate pinning is configured and validate certificates strictly during all CPI-vCenter communications.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-41012. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart