Security Vulnerability Report
中文
CVE-2026-9862 CVSS 9.8 CRITICAL

CVE-2026-9862

Published: 2026-06-15 16:16:35
Last Modified: 2026-06-15 16:16:35
Source: df4dee71-de3a-4139-9588-11b62fe6c0ff

Description

Fortra's  Core Privileged Access Manager (BoKS) contains an OS command injection vulnerability in the boks_autoregisterd service. A remote attacker with network access to the service may be able to cause commands to be executed with the privileges of the service during the autoregistration processing.

CVSS Details

CVSS Score
9.8
Severity
CRITICAL
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Configurations (Affected Products)

No configuration data available.

Fortra Core Privileged Access Manager (BoKS) 存在漏洞版本

PoC / Exploit Code

⚠ For Security Research Only
The following code is for security research and authorized testing only.
python
# PoC代码不可用 # 请勿尝试利用此漏洞 # 建议联系Fortra官方获取补丁信息

References

Raw JSON Data

JSON
{"cve": {"id": "CVE-2026-9862", "sourceIdentifier": "df4dee71-de3a-4139-9588-11b62fe6c0ff", "published": "2026-06-15T16:16:35.357", "lastModified": "2026-06-15T16:16:35.357", "vulnStatus": "Received", "cveTags": [], "descriptions": [{"lang": "en", "value": "Fortra's \nCore Privileged Access Manager (BoKS) contains an OS command injection vulnerability in the boks_autoregisterd service. A remote attacker with network access to the service may be able to cause commands to be executed with the privileges of the service during the autoregistration processing."}], "metrics": {"cvssMetricV31": [{"source": "df4dee71-de3a-4139-9588-11b62fe6c0ff", "type": "Secondary", "cvssData": {"version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "baseScore": 9.8, "baseSeverity": "CRITICAL", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH"}, "exploitabilityScore": 3.9, "impactScore": 5.9}]}, "weaknesses": [{"source": "df4dee71-de3a-4139-9588-11b62fe6c0ff", "type": "Secondary", "description": [{"lang": "en", "value": "CWE-78"}]}], "references": [{"url": "https://www.fortra.com/security/advisories/product-security/fi-2026-007", "source": "df4dee71-de3a-4139-9588-11b62fe6c0ff"}]}}