CVE-2026-12627

Summary

Fortra's Core Privileged Access Manager (BoKS) contains a stack-based buffer overflow vulnerability in boks_autoregisterd. A remote attacker with network access to the autoregistration service may be able to trigger memory corruption during client response processing.

Affected Software

VendorProductVersion RangeStatus
FortraFortra’s Core Privileged Access Manager (BoKS)8.1.0.0 <= 8.1.0.23affected
FortraFortra’s Core Privileged Access Manager (BoKS)9.0.0.0 <= 9.0.0.6affected

Weaknesses

  • CWE-121: CWE-121 Stack-based buffer overflow

Workarounds

Restrict network access to boks_autoregisterd, which listens on port 6507 by default. If autoregistration is not required, disable the boks_autoregisterd service until fixed builds are installed.

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: yes
    • Technical Impact: total

References