External risk intelligence

Fortra BoKS Manager Command Injection Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.1)

CVE-2026-79898

The vulnerability exists in the Fortra BoKS Manager, which includes network-accessible administration paths via REST or SOAP APIs. While these management interfaces are designed for administrative access, they are not typically exposed directly to the public internet in common secure deployments, though they are reachable from the network.

OS Command Injection

Halo Surface Signal: 3 out of 5 — possibly public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory details a critical command injection vulnerability within Fortra BoKS Manager. An authenticated administrator could exploit this flaw to execute arbitrary commands as the root user on the BoKS Master server, potentially impacting the confidentiality, integrity, and availability of the system. The primary concern is confirming if the affected technology is in use and if exposure exists within your environment.

  • Allows remote command execution as root.
  • Confirms administrative control system exposure.
  • Assess relevance and confirm potential impact.

Attack Path

How an attacker could exploit the issue

An attacker with administrative access to Fortra BoKS Manager can exploit a command injection vulnerability within the `crlserver` component. By adding a specially crafted CRL URL through various administrative interfaces, the attacker can trick the `crlserver` into executing arbitrary commands as the root user on the BoKS Master server, potentially leading to a full system compromise.

  • Requires administrative access.
  • Triggers via adding CRL URLs.
  • Risk of root command execution.

Live Threat

Current exploitation, exposure, and threat context

A command injection vulnerability in Fortra BoKS Manager's `crlserver` could allow an authenticated user to execute arbitrary commands as the root user on the BoKS Master server. This could occur when adding CRL URLs through various administrative interfaces, provided the user has the necessary permissions and the interface is accessible.

  • BoKS Master server and its root privileges.
  • Adding CRL URLs via administrative interfaces.
  • Compromise of the BoKS Master server.

Operational Fix

Recommended remediation, mitigation, and detection steps

The Fortra BoKS Master server is at risk from authenticated users who can inject commands via the CRL URL functionality. Infrastructure or platform teams managing BoKS are likely responsible for assessing and remediating this, coordinating with security teams to understand exposure and plan for potential root-level compromise. The first step is to identify all BoKS Master instances, verify network reachability, and confirm administrative access controls.

  • Identify BoKS Master instances and exposure.
  • Verify administrative access and control scope.
  • Plan remediation based on risk and impact.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Fortra BoKS Manager used for?

Fortra BoKS Manager is a central administration component used for identity and access management. It functions as the master server in the BoKS ecosystem, allowing authorized administrators to manage system configurations, security policies, and critical administrative tasks like certificate revocation list (CRL) handling.

What does CWE-78 mean for CVE-2026-79898?

CWE-78 refers to OS Command Injection. In the context of this vulnerability, it means the software fails to properly sanitize input before passing it to a system shell. Because of this, the crlserver component can be tricked into executing unintended, malicious operating system commands with full root-level privileges.

How is the command injection triggered?

The vulnerability is triggered when an authenticated user adds a specially crafted URL to the CRL configuration. The bug is tied specifically to the CRL URL input process. Regular administrative tasks that do not involve submitting or modifying CRL URLs through the affected APIs or command-line interfaces do not trigger this flaw.

How relevant is this CVE based on Halo Surface Signal?

According to Halo Surface Signal, this vulnerability is relevant because the Fortra BoKS Manager includes administration paths via REST or SOAP APIs that are network-accessible. While these interfaces are not meant to be public, they remain reachable from within a network, increasing the risk if those internal access points are not strictly protected.

What should I do first to manage this risk?

Start by identifying all BoKS Master instances in your environment. Once identified, verify which administrative interfaces—such as BCC, WSI REST/SOAP APIs, or the cacrl command-line tool—are reachable on your network and audit who has the administrative credentials necessary to perform configuration changes like adding CRL URLs.

References