CVE-2026-12627: Fortra's Core Privileged Access Manager (BoKS) autoregistration stack buffer overflow vulnerability
Fortra's Core Privileged Access Manager (BoKS) contains a stack-based buffer overflow vulnerability in boksautoregisterd. A remote attacker with network access to the autoregistration service may be able to trigger memory corruption during client response processing.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
boks-serverto a version that resolves this vulnerability.Fixed in 8.1.0.24 - Upgrade
Upgrade
boks-serverto a version that resolves this vulnerability.Fixed in 9.0.0.7
Event History
Frequently Asked Questions
Which systems are exposed to remote exploitation?
Systems running Fortra Core Privileged Access Manager (BoKS) are exposed if their boks_autoregisterd autoregistration service is reachable by an attacker over the network.
What access or interaction does an attacker need?
An attacker needs network access to the autoregistration service. No privileges or user interaction are required according to the provided severity vector.
What part of the service processes the malicious input?
The issue can be triggered during client response processing in boks_autoregisterd, where a stack-based buffer overflow may cause memory corruption.