Description
Fortra's Core Privileged Access Manager (BoKS) contains a stack-based buffer overflow vulnerability in boks_autoregisterd. A remote attacker with network access to the autoregistration service may be able to trigger memory corruption during client response processing.
Published: 2026-10-01
Score: 9.8 Critical
EPSS: n/a
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

Fortra's Core Privileged Access Manager (BoKS) contains a stack-based buffer overflow in the boks_autoregisterd service. The flaw can be triggered by a remote attacker with network access, allowing memory corruption that can lead to arbitrary code execution. The vulnerability can compromise confidentiality, integrity, and availability of the BoKS system.

Affected Systems

All installations of Fortra's Core Privileged Access Manager (BoKS) running boks-server versions older than 8.1.0.24 or 9.0.0.7 are affected. The boks_autoregisterd service, which listens on port 6507 by default, is the entry point.

Risk and Exploitability

The CVSS score of 9.8 indicates critical severity, and the absence of an EPSS score means the current exploitation probability is unknown. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires only network connectivity to the autoregistration service, making the attack vector remote.

Generated by OpenCVE AI on October 1, 2026 at 16:20 UTC.

Remediation

Vendor Solution

Upgrade to boks-server 8.1.0.24 or 9.0.0.7.


Vendor Workaround

Restrict network access to boks_autoregisterd, which listens on port 6507 by default. If autoregistration is not required, disable the boks_autoregisterd service until fixed builds are installed.


OpenCVE Recommended Actions

  • Upgrade the BoKS server to version 8.1.0.24 or 9.0.0.7.
  • If an upgrade is not feasible immediately, restrict or block network access to the boks_autoregisterd service on port 6507 or disable the service until the patch is applied.
  • Implement firewall rules to prevent external access to port 6507 and monitor for unusual traffic toward the autoregistration endpoint.

Generated by OpenCVE AI on October 1, 2026 at 16:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 15:45:00 +0000

Type Values Removed Values Added
Description Fortra's Core Privileged Access Manager (BoKS) contains a stack-based buffer overflow vulnerability in boks_autoregisterd. A remote attacker with network access to the autoregistration service may be able to trigger memory corruption during client response processing.
Title Fortra's Core Privileged Access Manager (BoKS) autoregistration stack buffer overflow vulnerability
Weaknesses CWE-121
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Fortra

Published:

Updated: 2026-10-01T16:02:27.366Z

Reserved: 2026-06-18T15:02:55.446Z

Link: CVE-2026-12627

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-01T16:17:40.480

Modified: 2026-10-01T17:17:20.480

Link: CVE-2026-12627

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T16:30:10Z

Weaknesses
  • CWE-121

    Stack-based Buffer Overflow