SECURITYCRITICALCVE-2026-79898

CVE-2026-79898: Authenticated Command Injection to Root in Fortra BoKS Manager

An authenticated user who can add CRL URLs in Fortra BoKS Manager can trigger shell command injection, executing as root on the BoKS Master.

Dylan H.

Security Team

October 1, 2026
6 min read
CVE-2026-79898: Authenticated Command Injection to Root in Fortra BoKS Manager

Critical severity

Rated critical. Prioritise patching — see the remediation guidance below.

Affected Products

  • Fortra BoKS Manager — crlserver component on the BoKS Master (versions 8.1.0.0 through 8.1.0.23, and 9.0.0.0 through 9.0.0.6)

Overview

Fortra's BoKS Manager — the privileged access management (PAM) platform built around the "BoKS Master" server — is affected by CVE-2026-79898, a critical (CVSS 9.1) OS command injection vulnerability in crlserver, the component that processes Certificate Revocation List (CRL) URLs. An authenticated user who is authorized to add CRL URLs — through the BoKS Control Console (BCC), the WSI REST or SOAP API, or the cacrl command-line interface — can smuggle shell command substitution into a CRL URL value. When crlserver later processes that value, the injected commands execute as root on the BoKS Master, the server that anchors privileged access control for the whole BoKS deployment.

Published October 1, 2026 and tracked by Fortra under advisory FI-2026-015, the flaw is especially severe given what BoKS Manager is used for: it is the control plane enterprises rely on to broker and audit privileged (often root/administrator) access across Unix, Linux, and other managed systems. A root compromise of the BoKS Master itself undermines the trust anchor the rest of the PAM deployment depends on.


Technical Details

FieldValue
CVE IDCVE-2026-79898
SeverityCritical — CVSS 3.1 base score 9.1 (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H)
CWECWE-78 — Improper Neutralization of Special Elements used in an OS Command ("OS Command Injection")
Attack VectorNetwork — requires an authenticated account already authorized to add CRL URLs. BCC and WSI are network-reachable administration paths; non-root use of cacrl additionally requires a local sudo/suexec rule
Affected VersionFortra BoKS Manager 8.1.0.0 through 8.1.0.23, and 9.0.0.0 through 9.0.0.6
Fix StatusCovered by Fortra advisory FI-2026-015. Third-party trackers place the fix in the 8.1.0.24 / 9.0.0.7 line (the same release that resolves the related CVE-2026-79900), but that specific build number is not directly confirmed from Fortra's own advisory text in the sources available here — verify the exact fixed build against FI-2026-015 before relying on a version number

Exploitation status: Not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog as of publication, and no standalone public proof-of-concept or exploit has been identified. Exploitation requires pre-existing authorization to manage CRL URLs, which narrows the population of users who can trigger it — but does not require interactive/local access when reached via BCC or the WSI API.


How It Works

BoKS Manager lets authorized administrators configure Certificate Revocation List (CRL) URLs — endpoints the BoKS Master polls to check whether certificates used in its PKI-backed authentication paths have been revoked. That CRL URL value can be supplied through three different interfaces: the BoKS Control Console (BCC) GUI, the WSI REST or SOAP API, or the cacrl command-line tool.

The crlserver component, which runs with root privileges on the BoKS Master, fails to adequately neutralize shell metacharacters in the submitted CRL URL before using it in a context where shell command substitution is evaluated (patterns such as backtick-wrapped commands or $(...)). An authorized user can therefore embed an arbitrary command inside what looks like a CRL URL field; when crlserver later processes that stored value, the shell substitution is evaluated and the attacker's command runs as root, not as the lower-privileged identity the user authenticated with.

Because BCC and the WSI API are network-accessible administration paths, an attacker only needs valid credentials with CRL-URL-management authorization and network reachability to the management interface — no additional local shell access or sudo rule is required for those two paths. The cacrl CLI path additionally requires that a non-root user already hold a sudo/suexec rule permitting its use, a narrower precondition.


Impact Assessment

Who Is At Risk

Any organization running an affected BoKS Manager build (8.1.0.0 through 8.1.0.23, or 9.0.0.0 through 9.0.0.6) that has delegated CRL-URL management to any account below full BoKS administrator trust — a common pattern where certificate/PKI maintenance is assigned to a narrower operational role than full BoKS Master administration. Because BoKS underpins privileged access control across the managed estate, compromising its root context has an outsized blast radius compared to a typical application server.

Potential Attack Chains

  1. A disgruntled or compromised lower-privileged account authorized only for CRL maintenance submits a crafted CRL URL via BCC or the WSI API.
  2. crlserver processes the stored value and evaluates the embedded shell command substitution as root on the BoKS Master.
  3. The attacker now has root-level code execution on the system that brokers and audits privileged access across the entire managed BoKS estate — enabling credential theft, policy tampering, audit-log manipulation, and backdoor persistence across every host BoKS manages.

Mitigation

Immediate Actions

  • Apply the fix referenced in Fortra advisory FI-2026-015 as soon as it is validated against your environment; confirm the exact patched build number directly from Fortra rather than relying on third-party inference.
  • Until patched, restrict which accounts are authorized to add or modify CRL URLs through BCC, WSI, and cacrl to the smallest possible set of fully-trusted administrators.
  • Restrict network reachability to the BCC and WSI interfaces to a management network or jump host, rather than leaving them broadly reachable.

Detection Opportunities

  • Audit BCC, WSI API, and cacrl logs for CRL URL values containing shell metacharacters (semicolons, pipes, ampersands, backticks, $().
  • Monitor crlserver's process tree on the BoKS Master for unexpected child processes or command-line arguments inconsistent with normal CRL-fetch behavior.
  • Review BoKS Master root-level activity logs for actions that don't correlate with an administrator session.

Defence-in-Depth

  • Apply least privilege to CRL-URL management authorization — treat it as a sensitive, root-adjacent capability rather than routine PKI housekeeping, since this advisory demonstrates it can be leveraged into full root compromise.
  • Segment the BoKS Master's management interfaces (BCC, WSI) onto a restricted administrative network.
  • Maintain independent, out-of-band monitoring of the BoKS Master itself, since a fully compromised PAM control plane can be used to suppress or falsify its own audit trail.

Background

Fortra's BoKS product line is a privileged access management platform widely deployed to centralize and audit root/administrator-equivalent access across Unix and Linux fleets. The "BoKS Master" is the authoritative server in a BoKS deployment, so a root-level command injection reachable by an authenticated, lower-privileged operator is a significant finding for a product whose entire value proposition is controlling and auditing privileged access elsewhere.

CVE-2026-79898 was disclosed alongside several other BoKS Manager issues in the same release cycle, including CVE-2026-79899, CVE-2026-79896, and CVE-2026-79900 (CVSS scores ranging from high to critical), as well as a separate, unrelated command injection in BoKS's legacy client upgrade tooling (CVE-2026-9863, Fortra advisory FI-2026-008) and a critical, unauthenticated command injection in the boks_autoregisterd service (CVE-2026-9862, CVSS 9.8). Organizations running BoKS Manager should treat this as a cluster of advisories to review together rather than a single isolated issue.


References