Command Injection Vulnerability in Fortra BoKS Manager
CVE-2026-79898

9.1CRITICAL

Key Information:

Vendor

Fortra

Vendor
CVE Published:
1 October 2026

What is CVE-2026-79898?

Fortra BoKS Manager is affected by a command injection vulnerability located in the crlserver component. This issue allows authenticated users, who have permissions to add Certificate Revocation List (CRL) URLs via the BCC, WSI REST, or SOAP API, to exploit the vulnerability. If successfully executed, this could result in shell command substitution being processed by crlserver as root on the BoKS Master. Notably, the BCC and WSI offer network-accessible administrative functions that don’t necessitate local sudo or suexec rules. However, non-root utilization of the cacrl command-line interface requires specific permissions, which adds complexity to the access control landscape.

Affected Version(s)

BoKS Manager 8.1.0.0 <= 8.1.0.23

BoKS Manager 9.0.0.0 <= 9.0.0.6

References

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.