CVE-2026-79898
Received Received - Intake

Command Injection in Fortra BoKS Manager

Vulnerability report for CVE-2026-79898, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-01

Last updated on: 2026-10-01

Assigner: Fortra

Description

Fortra BoKS Manager contains a command injection vulnerability in crlserver. An authenticated user authorized to add CRL URLs through BCC, the WSI REST or SOAP API, or the cacrl command-line interface could cause shell command substitution to be processed by crlserver as root on the BoKS Master. BCC and WSI provide network-accessible administration paths and do not require a local sudo or suexec rule; non-root use of cacrl requires such a rule.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-01
Last Modified
2026-10-01
Generated
2026-10-01
AI Q&A
2026-10-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
fortra boks_manager *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-78 The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Fortra BoKS Manager has a command injection flaw in its crlserver component. An authenticated user with permission to add CRL URLs via BCC, WSI REST/SOAP API, or cacrl CLI could exploit this to run arbitrary shell commands as root on the BoKS Master server.

Detection Guidance

To detect this vulnerability, check for unauthorized modifications to CRL URLs via BCC, WSI REST/SOAP API, or cacrl CLI. Monitor crlserver logs for unexpected shell command substitutions executed as root. Verify if authenticated users added suspicious CRL URLs.

Impact Analysis

This vulnerability allows attackers with authenticated access to execute commands as root on the BoKS Master server. This could lead to full system compromise, unauthorized data access, or disruption of services relying on BoKS Manager.

Compliance Impact

This vulnerability could lead to unauthorized root-level access on the BoKS Master system, potentially exposing sensitive data. This may violate compliance requirements under GDPR (data protection) and HIPAA (healthcare data security) due to unauthorized access risks.

Mitigation Strategies

Apply vendor patches or updates for Fortra BoKS Manager immediately. Disable or restrict access to BCC, WSI REST, SOAP API, and cacrl CLI for non-privileged users. Review and remove unnecessary sudo or suexec rules for cacrl. Monitor network traffic for unauthorized CRL URL modifications.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-79898. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart