HIGH🇬🇧 English

CVE-2026-9863

CVSS 7.5v3.1pub. 2026-06-15upd. 2026-07-28

Fortra BoKS Manager contains an OS command injection vulnerability in the client upgrade and patch tooling for legacy tar-based client installations. A malicious or compromised legacy tar-installed client selected for upgrade or patching may be able to cause commands to be executed on the BoKS Master during client version handling.

oryginał EN
CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
  • Fortra Core Privileged Access Manager Server

    APP
    Fortra
    8.1.0.0 – 8.1.0.23 (bez)9.0.0.0 – 9.0.0.5 (bez)
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
Tagi
Command Injection
CWE
Referencje

Powiązane podatności

CVE-2026-9862CRITICAL9.8PL ✓ten sam produkt

Command injection w Fortra Core Privileged Access Manager (BoKS) — boks_autoregisterd

CVE-2025-10035CRITICAL10.0⚠ KEVPL ✓ten sam vendor

Deserialization i command injection w Fortra GoAnywhere MFT (License Servlet)

CVE-2024-6633CRITICAL9.8PL ✓ten sam vendor

Domyślne poświadczenia bazy HSQLDB w Fortra FileCatalyst Workflow

CVE-2024-5276CRITICAL9.8PL ✓ten sam vendor

SQL Injection w Fortra FileCatalyst Workflow umożliwia modyfikację danych

CVE-2024-25153CRITICAL9.8PL ✓ten sam vendor

Path traversal w Fortra FileCatalyst Workflow umożliwiający RCE przez web shell