Executive Summary
A critical vulnerability, CVE-2026-9862, has been identified and patched in Fortra's BoKS Core Privileged Access Manager. This OS command injection flaw, rated CVSS 9.8, allows unauthenticated remote attackers to execute arbitrary commands with elevated privileges via the boks_autoregisterd service. The vulnerability exposes organizations to the risk of full system compromise, particularly those relying on BoKS for privileged access management. While there is no evidence of confirmed breaches, the vulnerability is under active discussion in the security community and is considered a high-priority risk. Immediate patching and mitigation are strongly advised.
Technical Information
CVE-2026-9862 is an OS command injection vulnerability in the boks_autoregisterd service of Fortra BoKS Core Privileged Access Manager. The service, which listens on TCP port 6507, is responsible for handling autoregistration of new hosts. Due to improper input sanitization, an attacker with network access can inject arbitrary operating system commands, which are executed with the privileges of the boks_autoregisterd process. This can result in unauthorized system control, data exfiltration, lateral movement, or service disruption.
The vulnerability is exploitable over the network without authentication or user interaction. Attackers can automate exploitation, making any exposed BoKS instance with the autoregistration service enabled a potential target. The flaw was discovered on May 27, 2026, publicly disclosed on June 15, 2026, and reported by multiple sources including GBHackers, NVD, and Fortra's official advisory.
The vulnerability is classified as CWE-78 (Improper Neutralization of Special Elements used in an OS Command), and exploitation can lead to remote code execution with service-level privileges, which are typically elevated in privileged access management environments.
Exploitation in the Wild
As of the time of writing, there are no confirmed public breaches or exploitation campaigns directly attributed to CVE-2026-9862. However, the vulnerability's ease of exploitation and criticality have led to widespread scanning and exploitation attempts, as reported by security researchers. Privileged Access Management (PAM) systems like BoKS are high-value targets for both criminal and nation-state actors due to their central role in authentication and authorization.
The vulnerability maps to several MITRE ATT&CK techniques, including Exploit Public-Facing Application (T1190), Command and Scripting Interpreter (T1059), and Exploitation for Privilege Escalation (T1068). No public proof-of-concept exploit code has been identified in major exploit databases as of October 2026.
Importantly, CVE-2026-9862 is NOT currently listed in CISA's Known Exploited Vulnerabilities (KEV) catalog. Therefore, there is no CISA-confirmed evidence of active exploitation at this time.
APT Groups using this vulnerability
There is currently no public attribution of CVE-2026-9862 exploitation to any specific Advanced Persistent Threat (APT) group. No sector or country-specific targeting has been reported. However, the vulnerability aligns with tactics, techniques, and procedures (TTPs) commonly used by APTs targeting identity and access management infrastructure for lateral movement and privilege escalation. Organizations in critical infrastructure, finance, healthcare, and government should remain vigilant, as PAM systems are frequent targets for sophisticated threat actors.
Affected Product Versions
The authoritative and up-to-date list of affected and fixed versions is available only in the official Fortra advisory (FI-2026-007). Public third-party sources do not provide a complete version matrix. Customers are strongly advised to consult the official advisory to determine if their deployment is affected and to identify the appropriate fixed release for upgrade.
Workaround and Mitigation
Organizations should take the following immediate actions:
Restrict network access to TCP port 6507, ensuring only trusted hosts and internal segments can communicate with the boks_autoregisterd service. Disable the boks_autoregisterd service if it is not required by editing the boksinit configuration on the BoKS Master system to comment out the autoregistration service entry, then reload the configuration or restart the service. Increase monitoring of port 6507 and review logs for unexpected command execution or anomalous activity associated with the boks_autoregisterd process. Enforce least privilege and strict network segmentation for all PAM-related infrastructure.
Fortra has published Security Advisory FI-2026-007 with remediation guidance and fixed version numbers. Administrators should apply the patch as soon as possible and follow all vendor recommendations for securing their environment.
Indicators of Compromise
The following caveat applies: Indicators of compromise are point-in-time and should be validated before enforcement. As of the time of writing, no public indicators of compromise (IOCs) have been published in open sources for CVE-2026-9862.
References
GBHackers: Fortra Access Manager Security Flaw Exposes Systems to Command Injection NVD: CVE-2026-9862 SentinelOne: CVE-2026-9862 Mondoo: CVE-2026-9862 Fortra Advisory FI-2026-007
Rescana is here for you
Rescana provides a comprehensive Third-Party Risk Management (TPRM) platform, empowering organizations to continuously monitor, assess, and mitigate cyber risks across their supply chain and vendor ecosystem. Our platform delivers actionable intelligence, automated workflows, and deep visibility into emerging threats, helping you stay ahead of evolving cyber risks. We are happy to answer any questions at info@rescana.com.



