Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Critical Microsoft SharePoint Server CVE-2023-29357 Lets Attackers Remotely Execute Code
August 12, 2026
Critical Windows AFD.sys Zero-Day Exploited by Lazarus Group
August 12, 2026
Critical Microsoft Outlook RCE Vulnerability Patched
August 12, 2026
Home/Vulnerabilities/Critical Fortra Access Manager CVE-2024-0763 lets attackers inject commands
Vulnerabilities

Critical Fortra Access Manager CVE-2024-0763 lets attackers inject commands

Key Takeaways A critical command injection flaw (CVE-2026-9862) has been discovered in Fortra’s Core Privileged Access Manager (BoKS). The vulnerability, rated 9.8 CVSS, allows unauthenticated...

Emy Elsamnoudy
Emy Elsamnoudy
June 17, 2026 3 Min Read
61 0

Key Takeaways

  • A critical command injection flaw (CVE-2026-9862) has been discovered in Fortra’s Core Privileged Access Manager (BoKS).
  • The vulnerability, rated 9.8 CVSS, allows unauthenticated remote attackers to execute arbitrary commands on affected systems.
  • The flaw resides in the boks_autoregisterd service, which listens on TCP port 6507 by default.
  • Fortra has released an advisory (FI-2026-007) detailing temporary mitigations while permanent patches are developed.

Fortra has issued a warning regarding a severe security vulnerability within its Core Privileged Access Manager (BoKS) software. This critical flaw, identified as CVE-2026-9862, could enable remote attackers to execute arbitrary operating system commands on vulnerable systems, posing a significant risk to organizations.

Table Of Content

  • Key Takeaways
  • Understanding the Vulnerability
  • Exploitation and Impact
  • Fortra’s Response and Mitigation
  • What You Should Do

Understanding the Vulnerability

The vulnerability is an OS command injection (CWE-78) flaw found within the boks_autoregisterd service of BoKS. This service is integral to the product’s autoregistration functionality, which automates the process of adding hosts to the privileged access management environment.

Rated with a CVSS score of 9.8, the flaw stems from improper neutralization of user-supplied input. This allows attackers to craft malicious requests during the autoregistration process, injecting and executing arbitrary commands on the underlying operating system. Security researchers have noted that the vulnerable service typically operates on TCP port 6507, making it accessible over the network in many default deployments.

Exploitation and Impact

An unauthenticated attacker with network access to the boks_autoregisterd service can exploit CVE-2026-9862 without requiring any user interaction or pre-existing privileges. Successful exploitation grants the attacker the ability to execute arbitrary commands with the privileges of the service, which can lead to a complete system compromise. The potential consequences include data manipulation, full system control, and disruption of critical services.

Given the severe nature of this vulnerability and the absence of authentication requirements for exploitation, it presents a substantial threat to organizations relying on BoKS for their privileged access management needs. Attackers could leverage this weakness to facilitate lateral movement within networks, escalate privileges, or deploy malicious software.

Fortra’s Response and Mitigation

Fortra has acknowledged the vulnerability, as detailed in advisory FI-2026-007. The flaw was initially identified on May 27, 2026, and publicly disclosed on June 15, 2026. While security updates are under development, Fortra has provided temporary mitigation strategies.

Organizations are strongly urged to restrict network access to the boks_autoregisterd service. This can be achieved by implementing stringent firewall rules or network segmentation to limit exposure of port 6507, especially from untrusted network segments.

As an additional workaround, administrators can entirely disable the vulnerable service. This involves editing the boksinit configuration file on the BoKS Master system to comment out the autoregisterd service entry. After modifying the configuration, the service manager must be reloaded, or the BoKS service restarted for the changes to take effect. While effective in preventing exploitation, this action will disable the autoregistration functionality until the configuration is reverted.

Security teams should actively monitor their environments for any suspicious activity related to the autoregistration service, including unexpected command execution events or unusual network traffic targeting port 6507. Applying vendor-provided patches promptly upon their release will be essential for a complete remediation of this critical risk.

The disclosure of CVE-2026-9862 highlights the persistent dangers associated with exposed management services and underscores the critical importance of robust secure coding practices, particularly rigorous input validation, to prevent command injection vulnerabilities.

What You Should Do

  • Immediately restrict network access to the boks_autoregisterd service (TCP port 6507) using firewalls or network segmentation.
  • Consider temporarily disabling the boks_autoregisterd service by commenting out its entry in the boksinit configuration file on the BoKS Master system, then reloading the service manager or restarting BoKS.
  • Monitor your network and systems for any unusual activity targeting port 6507 or unexpected command execution.
  • Prepare to apply official vendor patches as soon as Fortra releases them to fully address the vulnerability.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackCVEExploitMalwarePatchSecurityVulnerability

Share Article

Emy Elsamnoudy

Emy Elsamnoudy

Emy is a cybersecurity analyst and reporter specializing in threat hunting, defense strategies, and industry trends. With expertise in proactive security measures, Emily covers the tools and techniques organizations use to detect and prevent cyber attacks. She is a regular speaker at security conferences and has contributed to industry reports on threat intelligence and security operations. Emily's reporting focuses on helping organizations improve their security posture through practical, actionable insights.

Previous Post

U.S. Commerce Dept Imposes Export Controls on Anthropic’s Claude Mythos 5 and Fable 5

Next Post

CISA Warns of Critical Oracle PeopleSoft 0-Day Actively Exploited

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
DEF CON Attendees Broadcast Fake Wi-Fi Network on Flight
August 11, 2026
Critical CopyEscape Docker Vulnerability Exposes Host Files to Root Overwrite
August 11, 2026
Intel’s $20 Billion Stock Sale Sparks Debate on Chip Supply Chain Security
August 11, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Emy Elsamnoudy
Emy Elsamnoudy
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us