GPU VulnDB

Database/Control plane, storage & DevOps

Fortra BoKS Manager: command injection in crlserver gives root on the BoKS Master via a crafted CRL URL

CVSS 9.1CVE-2026-79898Control plane, storage & DevOpscurated

Impact

BoKS Manager is the privileged-access and keystroke-control layer enterprises put in front of their Unix and Linux server estates - it decides who may become root on which host. An administrator authorized to add CRL URLs can get shell command substitution processed by crlserver as root on the BoKS Master. The Master is the policy authority for every enrolled host, so root there means control over access decisions across the managed fleet, which on a GPU estate is every login and every privileged action on the compute nodes. CVSS scope is marked changed (S:C) for this reason. Two of the three entry points - BCC and the WSI REST/SOAP API - are network-accessible administration paths and need no local sudo or suexec rule; only non-root use of the cacrl CLI does.

Who can reach it

An authenticated user already authorized to add CRL URLs, through the BCC console, the WSI REST or SOAP API, or the cacrl CLI. High privilege required (PR:H), but reachable over the network via BCC/WSI.

What to do

Apply the fix from Fortra advisory FI-2026-015; the record here does not name a fixed version, so take it from the advisory. Patching the BoKS Master means updating and restarting the BoKS server processes on the Master - the enrolled hosts are not touched, but access decisions depend on the Master, so schedule it like any change to the authentication path. Interim mitigation is to audit and tighten who is authorized to add CRL URLs and who can reach BCC and the WSI API.

References

Related entries

All Control plane, storage & DevOps entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.