CVE-2026-9862
critical · 9.8Fortra's Core Privileged Access Manager (BoKS) contains an OS command injection vulnerability in the boks_autoregisterd service. A remote attacker with network access to the service may be able to cause commands to be executed with the privileges of the service during the autoregistration processing.
9.8
CVSS
1.0%
EPSS (exploit prob.)
61st
EPSS percentile
2026-06-15
Published
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-78
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| fortra | core_privileged_access_manager_server | >= 8.1.0.0, < 8.1.0.23 |
| fortra | core_privileged_access_manager_server | >= 9.0.0.0, < 9.0.0.5 |
Check a specific version with /api/v1/cve/match.
References
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2026-9862