CVE-2026-79898: Fortra BoKS Manager crlserver command injection vulnerability
Fortra BoKS Manager contains a command injection vulnerability in crlserver. An authenticated user authorized to add CRL URLs through BCC, the WSI REST or SOAP API, or the cacrl command-line interface could cause shell command substitution to be processed by crlserver as root on the BoKS Master. BCC and WSI provide network-accessible administration paths and do not require a local sudo or suexec rule; non-root use of cacrl requires such a rule.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
boks-serverto a version that resolves this vulnerability.Fixed in 8.1.0.24 - Upgrade
Upgrade
boks-serverto a version that resolves this vulnerability.Fixed in 9.0.0.7
Event History
Frequently Asked Questions
Which users and interfaces can be used to exploit this issue?
An authenticated user who is authorized to add CRL URLs can exploit it through BCC, the WSI REST API, the WSI SOAP API, or the cacrl command-line interface. BCC and WSI are network-accessible administration paths.
Does exploitation require local privileged execution access?
Not when using BCC or WSI, because those interfaces do not require a local sudo or suexec rule. For non-root use of the cacrl command-line interface, a sudo or suexec rule is required.
What is the resulting privilege level if exploitation succeeds?
Shell command substitution is processed by crlserver as root on the BoKS Master. An attacker therefore needs authenticated CRL-URL administration authorization, but successful exploitation executes in the root context.