CVE-2026-9862: Unauthenticated OS Command Injection in Fortra Core Privileged Access Manager (BoKS) boks_autoregisterd — Threadlinqs Intelligence
As of 2026-06-20, CVE-2026-9862: Unauthenticated OS Command Injection in Fortra Core Privileged Access Manager (BoKS) boks_autoregisterd is a critical-severity vulnerability threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 17 indicators of compromise.
Threat ID: TL-2026-0885 · Severity: CRITICAL · CVSS: 9.8 · Status: ACTIVE · Category: VULNERABILITY
CVE-2026-9862 is a CVSS 9.8 unauthenticated OS command injection (CWE-78) in the boks_autoregisterd autoregistration service of Fortra Core Privileged Access Manager (BoKS), reachable by default on
Fortra Core Privileged Access Manager (BoKS), formerly HelpSystems/PowerTech BoKS Manager, is an enterprise privileged-access-management (PAM) product for Linux and UNIX fleets. A central BoKS Master (with Replicas) brokers and enforces privileged access, SSH key management, keystroke logging, and least-privilege policy across managed hosts. Because the Master is the security control plane for an entire UNIX estate, a remote compromise of it is effectively a compromise of every host it governs.
CVE-2026-9862 is an OS command injection vulnerability (CWE-78, Improper Neutralization of Special Elements used in an OS Command) in the boks_autoregisterd daemon. This service implements the host autoregistration workflow, by which new client systems register themselves into the BoKS domain. The daemon listens by default on TCP port 6507 and, in many deployments, is network-reachable. Due to insufficient sanitization of attacker-controlled input handled during autoregistration processing, a crafted registration request can embed shell metacharacters (for example ';', '|', '`', or '$( )') that break out of the intended command context and are passed to an OS command interpreter. The injected commands execute with the privileges of the boks_autoregisterd service, which on the BoKS Master typically runs as root.
The CVSS 3.1 base score is 9.8 (Critical) with vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H: network attack vector, low complexity, no privileges, no user interaction, and high impact to confidentiality, integrity, and availability. Fortra's advisory states successful exploitation 'enables the execution of arbitrary commands with the service's privileges, which can lead to full system compromise, data manipulation, or service disruption.' Because the target is a PAM Master, post-exploitation impact extends well beyond a single host: an attacker can harvest stored privileged credentials and SSH keys, manipulate access policy, and pivot laterally across the managed UNIX fleet that BoKS centrally administers.
The flaw was identified by Fortra on May 27, 2026 and publicly disclosed on June 15, 2026 under advisory FI-2026-007, alongside a sibling command-injection flaw, CVE-2026-9863, in the boks_upgrade utility. Affected releases are BoKS server 8.1.0.0 through 8.1.0.22 and 9.0.0.0 through 9.0.0.4. Fixes shipped the same day in BoKS server 8.1.0.23 (which must be installed together with client package c-8.1.0.29 on Master or Replica systems) and 9.0.0.5. As of June 20, 2026 there is no public proof-of-concept, no confirmed in-the-wild exploitation, and the CVE is not listed in the CISA KEV catalog; EPSS is approximately 0.845% (~53rd percentile). The combination of unauthenticated network RCE, low attack complexity, and a high-value PAM target nonetheless makes this a priority-patch vulnerability. No threat-actor attribution and no real-world C2 or exploitation infrastructure are associated with this CVE; the indicators below are defensive hunting signals derived from the vulnerable service's mechanics, not observed adversary infrastructure.
Target sectors: financial, government, telecommunications, technology, healthcare, energy
Target regions: Global
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 17 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
VULNERABILITY, CRITICAL, threat intelligence, cybersecurity, CVE-2026-9862, T1595, T1592, T1190, T1059, T1106, T1543, T1098, T1136, T1053, T1068