Core Privileged Access Manager (BoKS) contains an OS command injection vulnerability in the boks_autoregisterd service. A remote attacker with network access to the service may be able to cause commands to be executed with the privileges of the service during the autoregistration processing.
Metrics
Affected Vendors & Products
No advisories yet.
Solution
Upgrade to boks-server 8.1.0.23 or 9.0.0.5.
Workaround
Restrict network access to boks_autoregisterd, which listens on port 6507 by default, until fixed builds are deployed. Another workaround for both boks-server 8.1 and 9.0 is to disable the service in the boksinit configuration. On the BoKS Master, edit $BOKS_var/internal/boksinit/master and comment out the line `autoregisterd:300:1:0:respawn::$BOKS_lib/boks_autoregisterd -xn` by prefixing it with `#`; then make boks_init reread the file, for example by running `kill -HUP $(cat $BOKS_var/run/boks_init)`, or restart BoKS. This stops boks_autoregisterd and prevents it from being respawned; autoregistration is unavailable until the row is restored.
Tue, 23 Jun 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Fortra
Fortra core Privileged Access Manager (boks) |
|
| Vendors & Products |
Fortra
Fortra core Privileged Access Manager (boks) |
Mon, 15 Jun 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 15 Jun 2026 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Fortra's Core Privileged Access Manager (BoKS) contains an OS command injection vulnerability in the boks_autoregisterd service. A remote attacker with network access to the service may be able to cause commands to be executed with the privileges of the service during the autoregistration processing. | |
| Title | Core Privileged Access Manager (BoKS) autoregistration service command injection vulnerability | |
| Weaknesses | CWE-78 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Fortra
Published:
Updated: 2026-06-15T16:09:28.297Z
Reserved: 2026-05-28T16:37:50.792Z
Link: CVE-2026-9862
Updated: 2026-06-15T16:09:23.776Z
Status : Analyzed
Published: 2026-06-15T16:16:35.357
Modified: 2026-07-28T13:20:39.080
Link: CVE-2026-9862
No data.
OpenCVE Enrichment
Updated: 2026-06-23T21:08:56Z