Insecure Temporary File in Core Privileged Access Manager (BoKS) - CVE-2026-79899
Published: October 6, 2026
Vulnerability details
The vulnerability allows a local user to disclose CA secret or host private-key material.
The vulnerability exists due to insecure temporary file creation in bccgethostcert when creating certificate-related temporary files. A local user can read predictable temporary files in BOKS_tmp to disclose CA secret or host private-key material.
User interaction is required.