Skip to main content
Mallory
Critical

OS Command Injection in Fortra Core Privileged Access Manager (BoKS) boks_autoregisterd

IdentifiersCVE-2026-9862CWE-78· Improper Neutralization of Special…

CVE-2026-9862 is an OS command injection vulnerability in Fortra Core Privileged Access Manager (BoKS), specifically in the boks_autoregisterd autoregistration service. During autoregistration processing, insufficient neutralization of attacker-controlled input can allow a remote attacker to inject and execute operating system commands. The issue is reachable over the network and does not require prior authentication or user interaction, provided the attacker can access the vulnerable service. Successful exploitation results in command execution in the security context of the boks_autoregisterd service.

Share:
For your environment

Are you exposed to this one?

Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.

ANALYST BRIEF

Impact, mitigation & remediation

What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.

Impact

What an attacker gets, and what they’ve been doing with it.

Successful exploitation allows a remote unauthenticated attacker with network access to the boks_autoregisterd service to execute arbitrary OS commands with the privileges of that service. Based on the provided CVSS vector (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H), the vulnerability can have high impact on confidentiality, integrity, and availability, including system compromise within the service's privilege boundary, unauthorized data access or modification, and service disruption.

Mitigation

If you can’t patch tonight, do this now.

Until fixed builds are deployed, restrict network access to boks_autoregisterd, which listens on port 6507 by default, to only strictly necessary trusted hosts or networks. As a workaround for both boks-server 8.1 and 9.0, disable the service in the boksinit configuration. On the BoKS Master, edit $BOKS_var/internal/boksinit/master and comment out the line autoregisterd:300:1:0:respawn::$BOKS_lib/boks_autoregisterd -xn by prefixing it with #; then force boks_init to reread the file, for example with kill -HUP $(cat $BOKS_var/run/boks_init), or restart BoKS. This stops boks_autoregisterd and prevents it from being respawned, though autoregistration remains unavailable until the configuration entry is restored.

Remediation

Patch, then assume compromise.

Apply the vendor-provided fixed builds referenced by Fortra advisory FI-2026-007 as soon as they are available and appropriate for the deployed BoKS version. Validate that the vulnerable boks_autoregisterd component is updated across affected systems and confirm the service is no longer exposed in a vulnerable state after patching.
PUBLIC EXPLOITS

Exploits

No public exploits tracked yet. Mallory keeps watching.

VALID 0 / 0 TOTALView more in app

No public exploit code observed for this vulnerability.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets are affected, which adversaries are exploiting it right now, which detections to deploy, and what to do tonight.
Exposure mapping

Query your assets running an affected version, and investigate the blast radius.

Threat actor evidence

Every observed campaign linking this CVE to a named adversary.

Associated malware

Malware families riding this exploit, with evidence and IOCs.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Vendor-by-vendor mapping

Cross-references every affected SKU, including bundled OEM variants.

Social activity6

Community discussion across Reddit, Mastodon, and other social sources.