---
id: CVE-2026-12627
title: >-
  Fortra's Core Privileged Access Manager (BoKS) autoregistration stack buffer
  overflow vulnerability
summary: >-
  Fortra's Core Privileged Access Manager (BoKS) contains a stack-based buffer
  overflow vulnerability in boks_autoregisterd. A remote attacker with network
  access to the autoregistration service may be able to trigger memory
  corruption dur…
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cvssSource: cna
cwe:
  - CWE-121
vendor: Fortra
product: Fortra's Core Privileged Access Manager (BoKS)
affected:
  - fortra_s_core_privileged_access_manager_boks >= 8.1.0.0 <= 8.1.0.23
  - fortra_s_core_privileged_access_manager_boks >= 9.0.0.0 <= 9.0.0.6
published: '2026-10-01'
updated: '2026-10-01'
sourceUpdated: '2026-10-01T15:29:41.772Z'
source: CVEORG
sourceUrl: 'https://www.cve.org/CVERecord?id=CVE-2026-12627'
references:
  - url: 'https://www.fortra.com/security/advisories/product-security/fi-2026-017'
tags:
  - cve.org
ingestedAt: '2026-10-01T15:48:17.833Z'
---

## Overview

Fortra's Core Privileged Access Manager (BoKS) contains a stack-based buffer overflow vulnerability in boks_autoregisterd. A remote attacker with network access to the autoregistration service may be able to trigger memory corruption during client response processing.

## Affected

- `fortra_s_core_privileged_access_manager_boks >= 8.1.0.0 <= 8.1.0.23`
- `fortra_s_core_privileged_access_manager_boks >= 9.0.0.0 <= 9.0.0.6`

## Remediation

Upgrade to boks-server 8.1.0.24 or 9.0.0.7.

### Workarounds

Restrict network access to boks_autoregisterd, which listens on port 6507 by default. If autoregistration is not required, disable the boks_autoregisterd service until fixed builds are installed.
