Fortra's  Core Privileged Access Manager (BoKS) contains an OS command injection vulnerability in the boks_autoregisterd service. A remote attacker with network access to the service may be able to cause commands to be executed with the privileges of the service during the autoregistration processing.
History

Mon, 15 Jun 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 15 Jun 2026 16:00:00 +0000

Type Values Removed Values Added
Description Fortra's  Core Privileged Access Manager (BoKS) contains an OS command injection vulnerability in the boks_autoregisterd service. A remote attacker with network access to the service may be able to cause commands to be executed with the privileges of the service during the autoregistration processing.
Title Core Privileged Access Manager (BoKS) autoregistration service command injection vulnerability
Weaknesses CWE-78
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Fortra

Published:

Updated: 2026-06-15T16:09:28.297Z

Reserved: 2026-05-28T16:37:50.792Z

Link: CVE-2026-9862

cve-icon Vulnrichment

Updated: 2026-06-15T16:09:23.776Z

cve-icon NVD

Status : Received

Published: 2026-06-15T16:16:35.357

Modified: 2026-06-15T16:16:35.357

Link: CVE-2026-9862

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.