PT-2026-49246 · Fortra · Ca Privileged Access Manager

Published

2026-06-15

·

Updated

2026-06-15

·

CVE-2026-9863

CVSS v3.1

7.5

High

VectorAV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Fortra BoKS Manager contains an OS command injection vulnerability in the client upgrade and patch tooling for legacy tar-based client installations. A malicious or compromised legacy tar-installed client selected for upgrade or patching may be able to cause commands to be executed on the BoKS Master during client version handling.

Fix

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2026-9863

Affected Products

Ca Privileged Access Manager