Project Subscriptions
No data.
No advisories yet.
Solution
Upgrade to boks-server 8.1.0.23 or 9.0.0.5.
Workaround
Until fixed builds are deployed, only run BoKS client upgrade or patch operations for legacy tar-based client installations against trusted clients. Avoid running boks_upgrade upgrade or patch operations for legacy tar-installed clients that may be compromised or controlled by an untrusted party.
Mon, 15 Jun 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 15 Jun 2026 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Fortra BoKS Manager contains an OS command injection vulnerability in the client upgrade and patch tooling for legacy tar-based client installations. A malicious or compromised legacy tar-installed client selected for upgrade or patching may be able to cause commands to be executed on the BoKS Master during client version handling. | |
| Title | Core Privileged Access Manager (BoKS) upgrade tooling command injection vulnerability | |
| Weaknesses | CWE-78 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Fortra
Published:
Updated: 2026-06-15T16:08:58.885Z
Reserved: 2026-05-28T16:37:53.223Z
Link: CVE-2026-9863
Updated: 2026-06-15T16:08:54.811Z
Status : Received
Published: 2026-06-15T16:16:35.507
Modified: 2026-06-15T16:16:35.507
Link: CVE-2026-9863
No data.
OpenCVE Enrichment
No data.