Fortra's Core Privileged Access Manager (BoKS) autoregistration stack buffer overflow vulnerability

FI-2026-017 - Fortra's Core Privileged Access Manager (BoKS) autoregistration stack buffer overflow vulnerability

Severity
Critical
Published Date
01-Oct-2026
Updated Date
01-Oct-2026
Vulnerabilities
CVE-2026-12627
 
Notes
Description

Fortra's Core Privileged Access Manager (BoKS) contains a stack-based buffer overflow vulnerability in boks_autoregisterd. A remote attacker with network access to the autoregistration service may be able to trigger memory corruption during client response processing.

 

Vulnerabilities

 
Fortra's Core Privileged Access Manager (BoKS) autoregistration stack buffer overflow vulnerability
Severity
Critical
CVE
CVE-2026-12627
CWE
CWE-121:Stack-based buffer overflow
Discovery Date
25-Aug-2026
CSSv3.1
9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Affected Products
Vulnerability Notes
References