CVE-2026-9862
Critical · CVSS 9.8- CVSS
- 9.8
- nvd
- EPSS
- 0.99%
- 59th pct
- KEV
- No
- Class
- other
- CWE-78
Description
Fortra's Core Privileged Access Manager (BoKS) contains an OS command injection vulnerability in the boks_autoregisterd service. A remote attacker with network access to the service may be able to cause commands to be executed with the privileges of the service during the autoregistration processing.
References
Status: profiled · ingested 2026-07-28T18:00:19.000Z