Stack-based Buffer Overflow Vulnerability in Fortra's Core Privileged Access Manager
CVE-2026-12627

9.8CRITICAL

Key Information:

Vendor

Fortra

Vendor
CVE Published:
1 October 2026

What is CVE-2026-12627?

Fortra's Core Privileged Access Manager (BoKS) is susceptible to a stack-based buffer overflow in the boks_autoregisterd component. This vulnerability may allow a remote attacker with access to the autoregistration service to exploit the flaw, potentially leading to memory corruption during the processing of client responses. Proper patching and security measures are crucial to mitigate this risk and protect against unauthorized access.

Affected Version(s)

Fortra's Core Privileged Access Manager (BoKS) 8.1.0.0 <= 8.1.0.23

Fortra's Core Privileged Access Manager (BoKS) 9.0.0.0 <= 9.0.0.6

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.