CVE-2026-79899
Received Received - Intake

Insecure Temporary File Handling in Fortra BoKS Manager

Vulnerability report for CVE-2026-79899, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-01

Last updated on: 2026-10-01

Assigner: Fortra

Description

Fortra BoKS Manager contains an insecure temporary file vulnerability in bccgethostcert. The utility creates predictable temporary files without first setting a restrictive umask. A local user on the BoKS Master who can read files under BOKS_tmp may be able to obtain CA secret or host private-key material while the utility runs, or obtain CA secret material left behind after successful certificate creation.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-01
Last Modified
2026-10-01
Generated
2026-10-01
AI Q&A
2026-10-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
fortra boks_manager *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-377 Creating and using insecure temporary files can leave application and system data vulnerable to attack.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Fortra BoKS Manager has an insecure temporary file vulnerability in the bccgethostcert utility. It creates predictable temporary files without setting a restrictive umask. A local user with access to BOKS_tmp files could read CA secrets or host private keys during or after the utility's execution.

Detection Guidance

Check for files under BOKS_tmp directory that may have predictable names or improper permissions. Look for temporary files created by bccgethostcert during execution. Verify umask settings for the utility to ensure restrictive permissions are enforced.

Impact Analysis

If you are a local user on the BoKS Master server with access to BOKS_tmp, an attacker could exploit this to steal sensitive cryptographic materials like CA secrets or host private keys. This could lead to unauthorized access, data breaches, or further compromise of the system.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating confidentiality requirements in GDPR and HIPAA. Organizations may face compliance violations, legal penalties, and reputational damage if exploited.

Mitigation Strategies

Update BoKS Manager to the latest version where this issue is fixed. Set a restrictive umask (e.g., 0077) for the bccgethostcert utility. Restrict access to BOKS_tmp directory to authorized users only. Monitor for unauthorized access to CA secrets or host private keys.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-79899. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart