Description
Fortra BoKS Manager contains an insecure temporary file vulnerability in bccgethostcert. The utility creates predictable temporary files without first setting a restrictive umask. A local user on the BoKS Master who can read files under BOKS_tmp may be able to obtain CA secret or host private-key material while the utility runs, or obtain CA secret material left behind after successful certificate creation.
Published: 2026-10-01
Score: 7.9 High
EPSS: n/a
KEV: No
Impact: Potential leakage of CA private keys and certificates
Action: Apply patch
AI Analysis

Impact

Fortra BoKS Manager includes an insecure temporary file vulnerability in bccgethostcert that produces predictable temporary files without setting a restrictive umask, allowing a local user who can read files in the BOKS_tmp directory to capture CA secret or host private‑key material while the utility runs or to retrieve leftover secret material after successful certificate creation.

Affected Systems

The vulnerability affects the Fortra BoKS Manager product; specific version information was not provided in the advisory.

Risk and Exploitability

The CVSS score of 7.9 indicates a high severity data‑exposure risk, while the EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog. A local attacker with read access to the BoKS Master’s temporary directory can exploit the weakness; the risk remains contingent on local privilege and directory accessibility.

Generated by OpenCVE AI on October 1, 2026 at 16:24 UTC.

Remediation

Vendor Solution

Upgrade to boks-server 8.1.0.24 or 9.0.0.7.


Vendor Workaround

Until a fixed release is installed, restrict local access to the BoKS Master and BOKS_tmp, invoke bccgethostcert with a restrictive umask such as 077, and securely remove any stale bcccax.* or bcccreds.* files from BOKS_tmp.


OpenCVE Recommended Actions

  • Upgrade to boks-server 8.1.0.24 or 9.0.0.7 to remove the vulnerability
  • Restrict local access to the BoKS Master and the BOKS_tmp directory so that only trusted users can read or write temporary files
  • When invoking bccgethostcert, set a restrictive umask such as 077 to limit file permissions of the temporary files
  • Remove any stale bcccax.* or bcccreds.* files from BOKS_tmp promptly before reuse

Generated by OpenCVE AI on October 1, 2026 at 16:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 01 Oct 2026 15:00:00 +0000

Type Values Removed Values Added
Description Fortra BoKS Manager contains an insecure temporary file vulnerability in bccgethostcert. The utility creates predictable temporary files without first setting a restrictive umask. A local user on the BoKS Master who can read files under BOKS_tmp may be able to obtain CA secret or host private-key material while the utility runs, or obtain CA secret material left behind after successful certificate creation.
Title Fortra BoKS Manager bccgethostcert insecure temporary file vulnerability
Weaknesses CWE-377
References
Metrics cvssV3_1

{'score': 7.9, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Fortra

Published:

Updated: 2026-10-01T15:28:05.358Z

Reserved: 2026-08-25T14:50:11.492Z

Link: CVE-2026-79899

cve-icon Vulnrichment

Updated: 2026-10-01T15:27:07.551Z

cve-icon NVD

Status : Received

Published: 2026-10-01T15:17:31.773

Modified: 2026-10-01T16:18:00.207

Link: CVE-2026-79899

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T16:30:10Z

Weaknesses