OS Command Injection in Core Privileged Access Manager (BoKS) - CVE-2026-9862
Published: June 19, 2026
Core Privileged Access Manager (BoKS)
Detailed vulnerability description
The vulnerability allows a remote attacker to execute arbitrary shell commands on the target system.
The vulnerability exists due to improper input validation within the boks_autoregisterd daemon when handling autoregistration events. A remote unauthenticated attacker can send specially crafted packets to port 6507 and execute arbitrary OS commands on the system with the privileges of the service during the autoregistration processing.