Junglewise Threat Intelligence

CVE-2026-9862: Fortra Core Privileged Access Manager OS command injection in boks_autoregisterd

CVE-2026-9862 · Severity: critical · CVSS 9.8 · Published 2026-06-15

Vendors: Fortra.

Executive brief

Fortra's Core Privileged Access Manager (BoKS) is a security solution used to manage and control administrative access to sensitive systems. A critical vulnerability has been identified that allows an unauthorized person to remotely execute commands on the system. This could lead to a complete takeover of the access management platform, potentially exposing all managed credentials and disrupting corporate security operations.

Technical details

An OS command injection vulnerability (CWE-78) exists within the boks_autoregisterd service of Fortra Core Privileged Access Manager (BoKS). The flaw is triggered during the autoregistration process, where insufficient neutralization of special elements allows a remote, unauthenticated attacker to inject and execute arbitrary operating system commands. The attack is reachable over the network and requires no user interaction. Successful exploitation grants the attacker the ability to execute commands with the privileges of the affected service, potentially leading to full system compromise.

Affected products

  • Fortra Core Privileged Access Manager (BoKS)

Timeline

  • 2026-06-15: disclosed
  • 2026-06-15: advisory

References