Description
Fortra BoKS Manager contains a command injection vulnerability in crlserver. An authenticated user authorized to add CRL URLs through BCC, the WSI REST or SOAP API, or the cacrl command-line interface could cause shell command substitution to be processed by crlserver as root on the BoKS Master. BCC and WSI provide network-accessible administration paths and do not require a local sudo or suexec rule; non-root use of cacrl requires such a rule.
Published: 2026-10-01
Score: 9.1 Critical
EPSS: n/a
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

Fortra BoKS Manager has a command injection flaw in crlserver, enabling an authenticated user who can add CRL URLs to run arbitrary shell commands as root on the master server. This vulnerability can lead to full system compromise, data loss, and service disruption, representing a critical security risk and covering CWE-78.

Affected Systems

The flaw affects Fortra BoKS Manager installations of the boks-server product line. Any version of boks-server earlier than 8.1.0.24 in the 8.x series or earlier than 9.0.0.7 in the 9.x series is impacted, especially when using the BCC tool, WSI REST/SOAP APIs, or the cacrl command‑line interface to add CRL URLs.

Risk and Exploitability

The CVSS score of 9.1 indicates a critical severity. Because the EPSS score is unavailable, the precise exploit probability is uncertain, yet the presence of network‑accessible administrative paths via BCC and WSI makes exploitation plausible. The flaw is not listed in the CISA KEV catalog. An attacker who authenticates to add a CRL URL—whether through a web‑service interface or the cacrl tool—can inject shell commands that execute with root privileges on the BoKS Master.

Generated by OpenCVE AI on October 1, 2026 at 16:23 UTC.

Remediation

Vendor Solution

Upgrade to boks-server 8.1.0.24 or boks-server 9.0.0.7, as appropriate for the installed maintenance line.


OpenCVE Recommended Actions

  • Upgrade to boks-server 8.1.0.24 or boks-server 9.0.0.7 to remove the vulnerability.
  • Restrict the use of BCC, WSI, and cacrl to trusted administrators only.
  • Limit network exposure of the BCC and WSI administrative interfaces to a secure, internal network or VPN.

Generated by OpenCVE AI on October 1, 2026 at 16:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 15:15:00 +0000

Type Values Removed Values Added
Description Fortra BoKS Manager contains a command injection vulnerability in crlserver. An authenticated user authorized to add CRL URLs through BCC, the WSI REST or SOAP API, or the cacrl command-line interface could cause shell command substitution to be processed by crlserver as root on the BoKS Master. BCC and WSI provide network-accessible administration paths and do not require a local sudo or suexec rule; non-root use of cacrl requires such a rule.
Title Fortra BoKS Manager crlserver command injection vulnerability
Weaknesses CWE-78
References
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Fortra

Published:

Updated: 2026-10-01T15:28:05.079Z

Reserved: 2026-08-25T14:50:10.463Z

Link: CVE-2026-79898

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-01T15:17:31.623

Modified: 2026-10-01T16:18:00.077

Link: CVE-2026-79898

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T16:30:10Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')