Insecure Temporary File Vulnerability in Fortra BoKS Manager
CVE-2026-79899
7.9HIGH
What is CVE-2026-79899?
Fortra BoKS Manager is susceptible to an insecure temporary file vulnerability that arises from its utility, bccgethostcert. The software creates predictable temporary files without establishing a restrictive umask, exposing sensitive information to local users on the BoKS Master. If a local user has the ability to read files within the BOKS_tmp directory, they may gain access to critical Certificate Authority (CA) secrets or private keys while the utility is operational, or discover CA secrets left unprotected after the successful creation of certificates.
Affected Version(s)
BoKS Manager 8.1.0.0 <= 8.1.0.23
BoKS Manager 9.0.0.0 <= 9.0.0.6