CVE-2026-79899 PUBLISHED

Fortra BoKS Manager bccgethostcert insecure temporary file vulnerability

Assigner: Fortra
Reserved: 25.08.2026 Published: 01.10.2026 Updated: 01.10.2026

Fortra BoKS Manager contains an insecure temporary file vulnerability in bccgethostcert. The utility creates predictable temporary files without first setting a restrictive umask. A local user on the BoKS Master who can read files under BOKS_tmp may be able to obtain CA secret or host private-key material while the utility runs, or obtain CA secret material left behind after successful certificate creation.

Metrics

CVSS Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N
CVSS Score: 7.9

Product Status

Vendor Fortra
Product BoKS Manager
Versions Default: unaffected
  • affected from 8.1.0.0 to 8.1.0.23 (incl.)
  • affected from 9.0.0.0 to 9.0.0.6 (incl.)

Workarounds

Until a fixed release is installed, restrict local access to the BoKS Master and BOKS_tmp, invoke bccgethostcert with a restrictive umask such as 077, and securely remove any stale bcccax. or bcccreds. files from BOKS_tmp.

Solutions

Upgrade to boks-server 8.1.0.24 or 9.0.0.7.

References

Problem Types

  • CWE-377: Insecure Temporary File CWE

Impacts

  • CAPEC-155 Screen Temporary Files for Sensitive Information