OCTOBER 6, 2026
Live Feed
Back to database
Case File

CVE-2026-79898

CRITICAL · CVSS 9.1 EPSS 0.98%

Source: NVD + CISA KEV + EPSS · Published 2026-10-01 · Last synced 2026-10-06

CyberRota Analysis

AI-Generated

Fortra BoKS Manager is vulnerable to a critical command injection flaw in the crlserver component, allowing authenticated users with permissions to add CRL URLs to execute arbitrary shell commands as root. This vulnerability poses a significant risk as it can be exploited through network-accessible administration interfaces without requiring elevated local privileges. Organizations using Fortra BoKS Manager should prioritize immediate remediation to mitigate potential unauthorized access and system compromise.

CVE
CVE-2026-79898
Severity
CRITICAL
CVSS
9.1
EPSS
0.98%

Original NVD Description

Fortra BoKS Manager contains a command injection vulnerability in crlserver. An authenticated user authorized to add CRL URLs through BCC, the WSI REST or SOAP API, or the cacrl command-line interface could cause shell command substitution to be processed by crlserver as root on the BoKS Master. BCC and WSI provide network-accessible administration paths and do not require a local sudo or suexec rule; non-root use of cacrl requires such a rule.