{"id":"CVE-2026-79899","title":"Fortra BoKS Manager contains an insecure temporary file vulnerability in bccgethostcert","summary":"Fortra BoKS Manager contains an insecure temporary file vulnerability in bccgethostcert. The utility creates predictable temporary files without first setting a restrictive umask. A local user on the BoKS Master who can read files under …","severity":"high","cvss":7.9,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N","cwe":["CWE-377"],"vendor":"Fortra","product":"BoKS Manager","affected":["boks_manager >= 8.1.0.0 <= 8.1.0.23","boks_manager >= 9.0.0.0 <= 9.0.0.6"],"published":"2026-10-01","updated":"2026-10-01","sourceUpdated":"2026-10-01T15:17:31.773","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-79899","references":[{"url":"https://www.fortra.com/security/advisories/product-security/fi-2026-014","label":"df4dee71-de3a-4139-9588-11b62fe6c0ff"}],"tags":["nvd","cve.org"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"total","timestamp":"2026-10-01T15:15:16.158691Z"},"ingestedAt":"2026-10-01T15:48:17.816Z","slug":"CVE-2026-79899","body":"## Overview\n\nFortra BoKS Manager contains an insecure temporary file vulnerability in bccgethostcert. The utility creates predictable temporary files without first setting a restrictive umask. A local user on the BoKS Master who can read files under BOKS_tmp may be able to obtain CA secret or host private-key material while the utility runs, or obtain CA secret material left behind after successful certificate creation.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":43,"depthScoreParts":{"impact":43.5,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}