Filtered by vendor Fortra Subscriptions
Filtered by product Core Privileged Access Manager (boks) Subscriptions
Total 2 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2026-9862 1 Fortra 1 Core Privileged Access Manager (boks) 2026-06-24 9.8 Critical
Fortra's  Core Privileged Access Manager (BoKS) contains an OS command injection vulnerability in the boks_autoregisterd service. A remote attacker with network access to the service may be able to cause commands to be executed with the privileges of the service during the autoregistration processing.
CVE-2026-9863 1 Fortra 1 Core Privileged Access Manager (boks) 2026-06-24 7.5 High
Fortra BoKS Manager contains an OS command injection vulnerability in the client upgrade and patch tooling for legacy tar-based client installations. A malicious or compromised legacy tar-installed client selected for upgrade or patching may be able to cause commands to be executed on the BoKS Master during client version handling.