OS Command Injection in Core Privileged Access Manager (BoKS) - CVE-2026-9862

 

OS Command Injection in Core Privileged Access Manager (BoKS) - CVE-2026-9862

Published: June 19, 2026


Vulnerability identifier: #VU134942
CSH Severity: Critical
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Red
CVE-ID: CVE-2026-9862
CWE-ID: CWE-78
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vendor: Fortra
Affected software:
Core Privileged Access Manager (BoKS)

Detailed vulnerability description

The vulnerability allows a remote attacker to execute arbitrary shell commands on the target system.

The vulnerability exists due to improper input validation within the boks_autoregisterd daemon when handling autoregistration events. A remote unauthenticated attacker can send specially crafted packets to port 6507 and execute arbitrary OS commands on the system with the privileges of the service during the autoregistration processing.


How to mitigate CVE-2026-9862

Install updates from vendor's website.

Sources