ZeroHour

CVE-2026-9862

CVSS 3.1
9.8 critical
EPSS
<1%p60
Published
()
Modified
Description

Fortra's Core Privileged Access Manager (BoKS) contains an OS command injection vulnerability in the boks_autoregisterd service. A remote attacker with network access to the service may be able to cause commands to be executed with the privileges of the service during the autoregistration processing.

Vendors
fortra
Products
core privileged access manager server
Weakness
CWE-78
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.