CVE-2026-9862
EUVD-2026-3673015.06.2026, 16:16
Fortra's Core Privileged Access Manager (BoKS) contains an OS command injection vulnerability in the boks_autoregisterd service. A remote attacker with network access to the service may be able to cause commands to be executed with the privileges of the service during the autoregistration processing.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| fortra | core_privileged_access_manager_server | 8.1.0.0 ≤ 𝑥 < 8.1.0.23 |
| fortra | core_privileged_access_manager_server | 9.0.0.0 ≤ 𝑥 < 9.0.0.5 |
𝑥
= Vulnerable software versions