---
id: CVE-2026-9862
title: "Fortra's\_\nCore Privileged Access Manager (BoKS)\_contains an OS command injection vulnerability in the boks_autoregisterd service"
summary: "Fortra's\_\nCore Privileged Access Manager (BoKS)\_contains an OS command injection vulnerability in the boks_autoregisterd service. A remote attacker with network access to the service may be able to cause commands to be executed with the …"
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-78
vendor: fortra
product: core_privileged_access_manager_server
affected:
  - 'core_privileged_access_manager_server >= 8.1.0.0, < 8.1.0.23'
  - 'core_privileged_access_manager_server >= 9.0.0.0, < 9.0.0.5'
patched:
  - core_privileged_access_manager_server 9.0.0.5
published: '2026-06-15'
updated: '2026-07-28'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-9862'
references:
  - url: 'https://www.fortra.com/security/advisories/product-security/fi-2026-007'
    label: df4dee71-de3a-4139-9588-11b62fe6c0ff
tags:
  - nvd
epss: 0.00992
epssPercentile: 0.6111
ingestedAt: '2026-07-28T18:38:09.132Z'
---

## Overview

Fortra's 
Core Privileged Access Manager (BoKS) contains an OS command injection vulnerability in the boks_autoregisterd service. A remote attacker with network access to the service may be able to cause commands to be executed with the privileges of the service during the autoregistration processing.

## Affected

- `core_privileged_access_manager_server >= 8.1.0.0, < 8.1.0.23`
- `core_privileged_access_manager_server >= 9.0.0.0, < 9.0.0.5`

## Remediation

Upgrade past the affected range:

- `core_privileged_access_manager_server 9.0.0.5`
