OS Command Injection in Core Privileged Access Manager (BoKS) - CVE-2026-9863
Published: June 19, 2026
Core Privileged Access Manager (BoKS)
Detailed vulnerability description
The vulnerability allows a remote attacker to execute arbitrary commands on the BoKS Master.
The vulnerability exists due to command injection in the client upgrade and patch tooling when handling client version information from a legacy tar-installed client selected for upgrade or patching. A remote attacker can provide a malicious or compromised legacy tar-installed client to execute arbitrary commands on the BoKS Master.
User interaction is required to initiate the upgrade or patch operation.