CVE-2026-9863
EUVD-2026-3673115.06.2026, 16:16
Fortra BoKS Manager contains an OS command injection vulnerability in the client upgrade and patch tooling for legacy tar-based client installations. A malicious or compromised legacy tar-installed client selected for upgrade or patching may be able to cause commands to be executed on the BoKS Master during client version handling.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| fortra | core_privileged_access_manager_server | 8.1.0.0 ≤ 𝑥 < 8.1.0.23 |
| fortra | core_privileged_access_manager_server | 9.0.0.0 ≤ 𝑥 < 9.0.0.5 |
𝑥
= Vulnerable software versions