CVE-2026-9862: Core Privileged Access Manager (BoKS) autoregistration service command injection vulnerability
Fortra's Core Privileged Access Manager (BoKS) contains an OS command injection vulnerability in the boksautoregisterd service. A remote attacker with network access to the service may be able to cause commands to be executed with the privileges of the service during the autoregistration processing.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Core Privileged Access Manager (BoKS) boks-serverto a version that resolves this vulnerability.Fixed in 8.1.0.23 - Upgrade
Upgrade
Core Privileged Access Manager (BoKS) boks-serverto a version that resolves this vulnerability.Fixed in 9.0.0.5
Event History
Frequently Asked Questions
What is the severity of CVE-2026-9862?
The severity of CVE-2026-9862 is critical, with a CVSS score of 9.8.
How can I mitigate CVE-2026-9862?
Mitigation for CVE-2026-9862 involves applying the latest security patches provided by Fortra for Core Privileged Access Manager (BoKS).
What type of vulnerability is CVE-2026-9862?
CVE-2026-9862 is an OS command injection vulnerability affecting the boks_autoregisterd service.
Who is affected by CVE-2026-9862?
Any organization using Fortra's Core Privileged Access Manager (BoKS) is potentially affected by CVE-2026-9862.
Can CVE-2026-9862 be exploited remotely?
Yes, CVE-2026-9862 can be exploited remotely by an attacker with network access to the boks_autoregisterd service.