CRITICAL🇵🇱 Wersja polska

CVE-2026-9862

CVSS 9.8v3.1pub. 2026-06-15upd. 2026-07-28

Fortra's  Core Privileged Access Manager (BoKS) contains an OS command injection vulnerability in the boks_autoregisterd service. A remote attacker with network access to the service may be able to cause commands to be executed with the privileges of the service during the autoregistration processing.

🤖 AI Analysis
How it works

The vulnerability (CWE-78) consists of insufficient sanitization of input data processed by the boks_autoregisterd service during the automatic registration process. An attacker with network access to this service can send crafted data containing malicious system commands. As a result, these commands are executed by the operating system with the privileges of the boks_autoregisterd process.

Impact

An attacker can execute arbitrary system commands with the privileges of the boks_autoregisterd service, which in practice can lead to system takeover, violation of data confidentiality and integrity, and disruption of its availability.

Mitigation & patch

Patches available from the vendor should be applied in accordance with the references (https://www.fortra.com/security/advisories/product-security/fi-2026-007). Until the patch is applied, it is recommended to restrict network access to the boks_autoregisterd service only to trusted hosts, for example using a firewall.

Who is affected

Fortra Core Privileged Access Manager (BoKS) — versions indicated in the vendor's references

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Fortra Core Privileged Access Manager Server

    APP
    Fortra
    8.1.0.0 – 8.1.0.23 (excl.)9.0.0.0 – 9.0.0.5 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Command Injection
CWE
References

Related vulnerabilities

CVE-2026-9863HIGH7.5same product

Fortra BoKS Manager contains an OS command injection vulnerability in the client upgrade and patch tooling for...

CVE-2025-10035CRITICAL10.0⚠ KEVPL ✓same vendor

Deserialization i command injection w Fortra GoAnywhere MFT (License Servlet)

CVE-2024-6633CRITICAL9.8PL ✓same vendor

Domyślne poświadczenia bazy HSQLDB w Fortra FileCatalyst Workflow

CVE-2024-5276CRITICAL9.8PL ✓same vendor

SQL Injection w Fortra FileCatalyst Workflow umożliwia modyfikację danych

CVE-2024-25153CRITICAL9.8PL ✓same vendor

Path traversal w Fortra FileCatalyst Workflow umożliwiający RCE przez web shell