CVE-2026-9863

HIGH WAF: High
CVSS 8.8 Published: 2026-06-15
CWE-78

Fortra BoKS Manager contains an OS command injection vulnerability in the client upgrade and patch tooling for legacy tar-based client installations. A malicious or compromised legacy tar-installed client selected for upgrade or patching may be able to cause commands to be executed on the BoKS Master during client version handling.

WAF Coverage Analysis

OS Command Injection High WAF Coverage

OWASP: A03:2021 Injection

932xxx - Remote Code Execution

Affected Software

VendorProductVersion
fortracore_privileged_access_manager_server8.1.0.0 - 8.1.0.23
fortracore_privileged_access_manager_server9.0.0.0 - 9.0.0.5

References

Back to CVE Database