OS Command Injection in Core Privileged Access Manager (BoKS) - CVE-2026-79898
Published: October 6, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary commands as root.
The vulnerability exists due to improper neutralization of special elements used in an OS command in crlserver when processing CRL URLs. A remote privileged user can add a CRL URL containing shell command substitution through BCC, the WSI REST or SOAP API, or the cacrl command-line interface to execute arbitrary commands as root.
BCC and WSI provide network-accessible administration paths.