Security Advisory

CVE-2026-9862

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-06-15 15:10:08
Last updated 2026-06-15 16:09:28
Assigner Fortra
CVSS score 9.8
State PUBLISHED

Description

Fortra's  Core Privileged Access Manager (BoKS) contains an OS command injection vulnerability in the boks_autoregisterd service. A remote attacker with network access to the service may be able to cause commands to be executed with the privileges of the service during the autoregistration processing.