Search
Search Results (4 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-12627 | 1 Fortra | 1 Core Privileged Access Manager (boks) | 2026-10-01 | 9.8 Critical |
| Fortra's Core Privileged Access Manager (BoKS) contains a stack-based buffer overflow vulnerability in boks_autoregisterd. A remote attacker with network access to the autoregistration service may be able to trigger memory corruption during client response processing. | ||||
| CVE-2026-14316 | 1 Fortra | 1 Core Privileged Access Manager (boks) | 2026-10-01 | 8.1 High |
| The revoked-key error path builds a human-readable failure reason using sprintf() into a heap buffer. The allocated buffer is too small for the final formatted message. When sprintf() writes the full message, it can write past the end of the heap allocation. | ||||
| CVE-2026-9862 | 1 Fortra | 2 Core Privileged Access Manager (boks), Core Privileged Access Manager Server | 2026-06-23 | 9.8 Critical |
| Fortra's Core Privileged Access Manager (BoKS) contains an OS command injection vulnerability in the boks_autoregisterd service. A remote attacker with network access to the service may be able to cause commands to be executed with the privileges of the service during the autoregistration processing. | ||||
| CVE-2026-9863 | 1 Fortra | 2 Core Privileged Access Manager (boks), Core Privileged Access Manager Server | 2026-06-23 | 7.5 High |
| Fortra BoKS Manager contains an OS command injection vulnerability in the client upgrade and patch tooling for legacy tar-based client installations. A malicious or compromised legacy tar-installed client selected for upgrade or patching may be able to cause commands to be executed on the BoKS Master during client version handling. | ||||
Page 1 of 1.