rootpwn

high · CVSS v3 7.9

CVE-2026-79899

Fortra BoKS Manager's bccgethostcert utility creates predictable temporary files without first setting a restrictive umask. A local user on

Overview

Fortra BoKS Manager's bccgethostcert utility creates predictable temporary files without first setting a restrictive umask. A local user on the BoKS Master with read access to BOKS_tmp may be able to access CA secret or host private-key material while the utility runs or from files left behind after certificate creation. This matters because exposure of CA or host private keys can undermine certificate trust and related access controls.

Description

Fortra BoKS Manager contains an insecure temporary file vulnerability in bccgethostcert. The utility creates predictable temporary files without first setting a restrictive umask. A local user on the BoKS Master who can read files under BOKS_tmp may be able to obtain CA secret or host private-key material while the utility runs, or obtain CA secret material left behind after successful certificate creation.

Impact

Confidentiality is the primary impact, with potential exposure of CA secret or host private-key material. Integrity and availability are less directly described, but exposed keys could weaken trust in certificates and enable unauthorized access to protected systems. Impacted parties include BoKS Master administrators, PKI operators, and any local accounts or services with read access to the BOKS_tmp directory.

Remediation

Apply the vendor patch or update when available. Until patched, restrict access to BOKS_tmp to the minimum required accounts and services, enforce a restrictive umask for certificate operations, and remove or securely archive leftover temporary files after certificate creation. Rotate CA or host private keys if exposure is suspected, and add monitoring for unauthorized access to BOKS_tmp and certificate-related files.

Risk context

High severity based on CVSS v3 7.9, with no EPSS score provided. Treat as a priority for BoKS Master systems where local untrusted users or services can access BOKS_tmp, especially where CA or host private keys are present.

Affected products

  • Fortra BoKS Manager
  • Fortra BoKS Manager bccgethostcert
  • BoKS Master

Scores

Severity
high
CVSS v2
6.2
CVSS v3
7.9
CVSS v4
—
EPSS
—

insecure-temp-file local-access private-key-exposure PKI Fortra BoKS umask confidentiality

← All CVEs