Insecure Temporary File Vulnerability in Fortra BoKS Manager
CVE-2026-79899

7.9HIGH

Key Information:

Vendor

Fortra

Vendor
CVE Published:
1 October 2026

What is CVE-2026-79899?

Fortra BoKS Manager is susceptible to an insecure temporary file vulnerability that arises from its utility, bccgethostcert. The software creates predictable temporary files without establishing a restrictive umask, exposing sensitive information to local users on the BoKS Master. If a local user has the ability to read files within the BOKS_tmp directory, they may gain access to critical Certificate Authority (CA) secrets or private keys while the utility is operational, or discover CA secrets left unprotected after the successful creation of certificates.

Affected Version(s)

BoKS Manager 8.1.0.0 <= 8.1.0.23

BoKS Manager 9.0.0.0 <= 9.0.0.6

References

CVSS V3.1

Score:
7.9
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.