CVE-2026-79898: Fortra Boks Manager

Critical severity, CVSS 9.1. EPSS: 1% chance of exploitation in the next 30 days.

Fortra BoKS Manager contains a command injection vulnerability in crlserver. An authenticated user authorized to add CRL URLs through BCC, the WSI REST or SOAP API, or the cacrl command-line interface could cause shell command substitution to be processed by crlserver as root on the BoKS Master. BCC and WSI provide network-accessible administration paths and do not require a local sudo or suexec rule; non-root use of cacrl requires such a rule.

Affected products

  • Fortra Boks Manager: from 8.1.0.0, up to and including 8.1.0.23; from 9.0.0.0, up to and including 9.0.0.6

Published 2026-10-01. Last modified 2026-10-01.