Fortra BoKS Manager contains an insecure temporary file vulnerability in bccgethostcert. The utility creates predictable temporary files without first setting a restrictive umask. A local user on the BoKS Master who can read files under BOKS_tmp may be able to obtain CA secret or host private-key material while the utility runs, or obtain CA secret material left behind after successful certificate creation.

Project Subscriptions

Vendors Products
Boks Manager Subscribe
Advisories

No advisories yet.

Fixes

Solution

Upgrade to boks-server 8.1.0.24 or 9.0.0.7.


Workaround

Until a fixed release is installed, restrict local access to the BoKS Master and BOKS_tmp, invoke bccgethostcert with a restrictive umask such as 077, and securely remove any stale bcccax.* or bcccreds.* files from BOKS_tmp.

History

Thu, 01 Oct 2026 20:00:00 +0000

Type Values Removed Values Added
First Time appeared Fortra
Fortra boks Manager
Vendors & Products Fortra
Fortra boks Manager

Thu, 01 Oct 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 01 Oct 2026 15:00:00 +0000

Type Values Removed Values Added
Description Fortra BoKS Manager contains an insecure temporary file vulnerability in bccgethostcert. The utility creates predictable temporary files without first setting a restrictive umask. A local user on the BoKS Master who can read files under BOKS_tmp may be able to obtain CA secret or host private-key material while the utility runs, or obtain CA secret material left behind after successful certificate creation.
Title Fortra BoKS Manager bccgethostcert insecure temporary file vulnerability
Weaknesses CWE-377
References
Metrics cvssV3_1

{'score': 7.9, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: Fortra

Published:

Updated: 2026-10-01T15:28:05.358Z

Reserved: 2026-08-25T14:50:11.492Z

Link: CVE-2026-79899

cve-icon Vulnrichment

Updated: 2026-10-01T15:27:07.551Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-01T15:17:31.773

Modified: 2026-10-01T20:34:26.287

Link: CVE-2026-79899

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T19:33:56Z

Weaknesses