OS Command Injection in Core Privileged Access Manager (BoKS) - CVE-2026-9862

 

OS Command Injection in Core Privileged Access Manager (BoKS) - CVE-2026-9862

Published: June 19, 2026


Vulnerability identifier: #VU134942
CSH Severity: Critical
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-9862
CWE-ID: CWE-78
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary shell commands on the target system.

The vulnerability exists due to improper input validation within the boks_autoregisterd daemon when handling autoregistration events. A remote unauthenticated attacker can send specially crafted packets to port 6507 and execute arbitrary OS commands on the system with the privileges of the service during the autoregistration processing.


Affected software

Core Privileged Access Manager (BoKS)

How to mitigate CVE-2026-9862

Install updates from vendor's website.


External References

Related Security Bulletins