VYPR

Core Privileged Access Manager (BoKS)

by Fortra

CVEs (3)

  • CVE-2026-9862CriJun 15, 2026
    risk 0.64cvss 9.8epss 0.01

    Fortra's  Core Privileged Access Manager (BoKS) contains an OS command injection vulnerability in the boks_autoregisterd service. A remote attacker with network access to the service may be able to cause commands to be executed with the privileges of the service during the…

  • CVE-2025-13532MedDec 16, 2025
    risk 0.40cvss 6.2epss 0.00

    Insecure defaults in the Server Agent component of Fortra's Core Privileged Access Manager (BoKS) can result in the selection of weak password hash algorithms.  This issue affects BoKS Server Agent 9.0 instances that support yescrypt and are running in a BoKS 8.1 domain.

  • CVE-2025-5141MedJun 17, 2025
    risk 0.36cvss 5.5epss 0.00

    A binary in the BoKS Server Agent component of Fortra's Core Privileged Access Manager (BoKS) on versions 7.2.0 (up to 7.2.0.17), 8.1.0 (up to 8.1.0.22), 8.1.1 (up to 8.1.1.7), 9.0.0 (up to 9.0.0.1) and also legacy tar installs of BoKS 7.2 without hotfix #0474 on Linux, AIX, and…