Command Injection Vulnerability in Fortra BoKS Manager
CVE-2026-79898
What is CVE-2026-79898?
Fortra BoKS Manager is affected by a command injection vulnerability located in the crlserver component. This issue allows authenticated users, who have permissions to add Certificate Revocation List (CRL) URLs via the BCC, WSI REST, or SOAP API, to exploit the vulnerability. If successfully executed, this could result in shell command substitution being processed by crlserver as root on the BoKS Master. Notably, the BCC and WSI offer network-accessible administrative functions that don’t necessitate local sudo or suexec rules. However, non-root utilization of the cacrl command-line interface requires specific permissions, which adds complexity to the access control landscape.
Affected Version(s)
BoKS Manager 8.1.0.0 <= 8.1.0.23
BoKS Manager 9.0.0.0 <= 9.0.0.6