OS Command Injection in Core Privileged Access Manager (BoKS) - CVE-2026-9863

 

OS Command Injection in Core Privileged Access Manager (BoKS) - CVE-2026-9863

Published: June 19, 2026


Vulnerability identifier: #VU134968
CSH Severity: Medium
CVSS v4: 7.5 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-9863
CWE-ID: CWE-78
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary commands on the BoKS Master.

The vulnerability exists due to command injection in the client upgrade and patch tooling when handling client version information from a legacy tar-installed client selected for upgrade or patching. A remote attacker can provide a malicious or compromised legacy tar-installed client to execute arbitrary commands on the BoKS Master.

User interaction is required to initiate the upgrade or patch operation.


Affected software

Core Privileged Access Manager (BoKS)

How to mitigate CVE-2026-9863

Install security update from vendor's website.


External References

Related Security Bulletins