Fortra's Core Privileged Access Manager (BoKS) contains an OS command injection vulnerability in the boks_autoregisterd service. A remote attacker with network access to the service may be able to cause commands to be executed with the privileges of the service during the autoregistration processing.
The vulnerability (CWE-78) consists of insufficient sanitization of input data processed by the boks_autoregisterd service during the automatic registration process. An attacker with network access to this service can send crafted data containing malicious system commands. As a result, these commands are executed by the operating system with the privileges of the boks_autoregisterd process.
An attacker can execute arbitrary system commands with the privileges of the boks_autoregisterd service, which in practice can lead to system takeover, violation of data confidentiality and integrity, and disruption of its availability.
Patches available from the vendor should be applied in accordance with the references (https://www.fortra.com/security/advisories/product-security/fi-2026-007). Until the patch is applied, it is recommended to restrict network access to the boks_autoregisterd service only to trusted hosts, for example using a firewall.
Fortra Core Privileged Access Manager (BoKS) — versions indicated in the vendor's references
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HFortra Core Privileged Access Manager Server
APPFortra8.1.0.0 – 8.1.0.23 (excl.)9.0.0.0 – 9.0.0.5 (excl.)
Related vulnerabilities
Fortra BoKS Manager contains an OS command injection vulnerability in the client upgrade and patch tooling for...
Deserialization i command injection w Fortra GoAnywhere MFT (License Servlet)
Domyślne poświadczenia bazy HSQLDB w Fortra FileCatalyst Workflow
SQL Injection w Fortra FileCatalyst Workflow umożliwia modyfikację danych
Path traversal w Fortra FileCatalyst Workflow umożliwiający RCE przez web shell