critical · CVSS v3 9.1
CVE-2026-79898
Fortra BoKS Manager contains a command injection vulnerability in crlserver that can be triggered when adding CRL URLs. An authenticated use
Overview
Fortra BoKS Manager contains a command injection vulnerability in crlserver that can be triggered when adding CRL URLs. An authenticated user with permission to manage CRL URLs through BCC, the WSI REST or SOAP API, or the cacrl CLI may cause shell command substitution to be processed as root on the BoKS Master. This matters because network-accessible administration paths can lead to full compromise of the BoKS Master.
Description
Fortra BoKS Manager contains a command injection vulnerability in crlserver. An authenticated user authorized to add CRL URLs through BCC, the WSI REST or SOAP API, or the cacrl command-line interface could cause shell command substitution to be processed by crlserver as root on the BoKS Master. BCC and WSI provide network-accessible administration paths and do not require a local sudo or suexec rule; non-root use of cacrl requires such a rule.
Impact
Confidentiality, integrity, and availability are all at high risk on affected BoKS Master systems. An authenticated user with CRL URL management rights, or an attacker with valid privileged credentials, could execute arbitrary commands as root. This could allow theft of sensitive identity or PKI data, tampering with CRL configuration, and disruption of BoKS services. Organizations relying on BoKS Manager for identity, access, or certificate revocation management are most impacted.
Remediation
Apply the vendor patch or hotfix for the crlserver command injection issue as soon as available. Restrict network access to BCC and WSI REST/SOAP administration endpoints to trusted management networks, VPNs, or jump hosts. Enforce least privilege and multi-factor authentication for accounts authorized to add or modify CRL URLs. Disable or remove unused BCC, WSI, or cacrl administration interfaces where possible. Monitor BoKS Manager logs for unusual CRL URL additions, crlserver process activity, and privileged account use. Segment the BoKS Master from general user networks and review local sudo or suexec rules for non-root cacrl usage.
Risk context
The reported CVSS v3 score is 9.1, indicating critical severity. No EPSS value is provided. Defenders should treat this as high urgency for exposed or privileged BoKS Manager deployments and prioritize patching, access restriction, and monitoring.
Affected products
- Fortra BoKS Manager
- Fortra BoKS Manager crlserver
- Fortra BoKS Manager BCC
- Fortra BoKS Manager WSI REST API
- Fortra BoKS Manager WSI SOAP API
- Fortra BoKS Manager cacrl CLI
Scores
- Severity
- critical
- CVSS v2
- 8.3
- CVSS v3
- 9.1
- CVSS v4
- —
- EPSS
- —