CVE-2026-79899High· 7.9▾ TwilightFortra BoKS Manager contains an insecure temporary file vulnerability in bccgethostcert. The utility creates predictable temporary files without first setting a restrictive umask. A local user on the BoKS Master who can read files under …
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 43.5 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Fortra BoKS Manager contains an insecure temporary file vulnerability in bccgethostcert. The utility creates predictable temporary files without first setting a restrictive umask. A local user on the BoKS Master who can read files under BOKS_tmp may be able to obtain CA secret or host private-key material while the utility runs, or obtain CA secret material left behind after successful certificate creation.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-79896High· 7.5Fortra BoKS Manager boks_portmux TLS ClientHello out-of-bounds read vulnerability
CVE-2026-79898Critical· 9.1Fortra BoKS Manager contains a command injection vulnerability in crlserver
CVE-2026-12627Critical· 9.8Fortra's Core Privileged Access Manager (BoKS) autoregistration stack buffer overflow vulnerability
CVE-2026-79900Medium· 6.5boks_ksllogsd accepts a checksum algorithm name in the MD field of an authenticated KSL start message
CVE-2026-79901Critical· 9.9In deployments using BoKS keytab management, affected versions of boks_keytabmd generate Active Directory service-account passwords from a predictable pseudo-random sequence seeded with the current Unix timestamp
CVE-2026-15913High· 7.7In versions prior to 7.10.2 a path traversal vulnerability in the /attachRemoteFiles endpoint of Fortra's GoAnywhere MFT allows Web Users with both Secure Folders and Secure Mail permissions to escape their sandboxed home directory, achi…