CVE-2026-9863 PUBLISHED

Core Privileged Access Manager (BoKS) upgrade tooling command injection vulnerability

Assigner: Fortra
Reserved: 28.05.2026 Published: 15.06.2026 Updated: 15.06.2026

Fortra BoKS Manager contains an OS command injection vulnerability in the client upgrade and patch tooling for legacy tar-based client installations. A malicious or compromised legacy tar-installed client selected for upgrade or patching may be able to cause commands to be executed on the BoKS Master during client version handling.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS Score: 7.5

Product Status

Vendor Fortra
Product Core Privileged Access Manager (BoKS)
Versions Default: unaffected
  • affected from boks-server 8.1.0.0 to boks-server 8.1.0.22 (incl.)
  • affected from boks-server 9.0.0.0 to boks-server 9.0.0.4 (incl.)

Workarounds

Until fixed builds are deployed, only run BoKS client upgrade or patch operations for legacy tar-based client installations against trusted clients. Avoid running boks_upgrade upgrade or patch operations for legacy tar-installed clients that may be compromised or controlled by an untrusted party.

Solutions

Upgrade to boks-server 8.1.0.23 or 9.0.0.5.

Credits

  • Fortra internal security assessment finder

References

Problem Types

  • CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') CWE

Impacts

  • CAPEC-248 Command Injection