OS Command Injection in Core Privileged Access Manager (BoKS) - CVE-2026-9863

 

OS Command Injection in Core Privileged Access Manager (BoKS) - CVE-2026-9863

Published: June 19, 2026


Vulnerability identifier: #VU134968
CSH Severity: Medium
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2026-9863
CWE-ID: CWE-78
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vendor: Fortra
Affected software:
Core Privileged Access Manager (BoKS)

Detailed vulnerability description

The vulnerability allows a remote attacker to execute arbitrary commands on the BoKS Master.

The vulnerability exists due to command injection in the client upgrade and patch tooling when handling client version information from a legacy tar-installed client selected for upgrade or patching. A remote attacker can provide a malicious or compromised legacy tar-installed client to execute arbitrary commands on the BoKS Master.

User interaction is required to initiate the upgrade or patch operation.


How to mitigate CVE-2026-9863

Install security update from vendor's website.

Sources