CVE-2026-9863
HIGH WAF: High
CVSS 8.8
Published: 2026-06-15
CWE-78
Fortra BoKS Manager contains an OS command injection vulnerability in the client upgrade and patch tooling for legacy tar-based client installations. A malicious or compromised legacy tar-installed client selected for upgrade or patching may be able to cause commands to be executed on the BoKS Master during client version handling.
WAF Coverage Analysis
OS Command Injection
High WAF Coverage
OWASP: A03:2021 Injection
932xxx - Remote Code Execution
Affected Software
| Vendor | Product | Version |
|---|---|---|
| fortra | core_privileged_access_manager_server | 8.1.0.0 - 8.1.0.23 |
| fortra | core_privileged_access_manager_server | 9.0.0.0 - 9.0.0.5 |
References
- www.fortra.com (Vendor Advisory)