Heap Buffer Overflow in Fortra's Security Product
CVE-2026-14316
8.1HIGH
Key Information:
- Vendor
Fortra
- Vendor
- CVE Published:
- 1 October 2026
What is CVE-2026-14316?
A vulnerability exists in Fortra's Security Product where the error management for revoked keys improperly constructs a human-readable failure message. The buffer allocated for this message is insufficient, allowing potential exploitation through a heap buffer overflow. This flaw could enable unintended memory writes, which may compromise the integrity and security of the affected systems.
Affected Version(s)
Core Privileged Access Manager (BoKS) 8.1.0.0 < 8.1.0.30
Core Privileged Access Manager (BoKS) 10.1.0.0 < 10.1.1.0