CVE-2026-79899
Fortra BoKS Manager enthält eine Schwachstelle durch unsichere temporäre Dateien in bccgethostcert.
highEPSS 0.1%
Description
Fortra BoKS Manager contains an insecure temporary file vulnerability in bccgethostcert. The utility creates predictable temporary files without first setting a restrictive umask. A local user on the BoKS Master who can read files under BOKS_tmp may be able to obtain CA secret or host private-key material while the utility runs, or obtain CA secret material left behind after successful certificate creation.
Source: NVD (NIST)cvelistv5
Metrics
Show all metrics
Severity
high
69.50
no public PoC known
7.9
Published
2026-10-01 14:37 UTC
CWE-377
Weakness classes (CWE)
CWE-377Class
Insecure Temporary File
Creating and using insecure temporary files can leave application and system data vulnerable to attack.
cwe.mitre.org →
References & sources
Reanalysis & status changes
Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.
- CVE Modified2026-10-01 16:18 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
- SSVC: {"id":"CVE-2026-79899","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalI…
- New CVE Received2026-10-01 15:17 UTC· df4dee71-de3a-4139-9588-11b62fe6c0ff
- Description: Fortra BoKS Manager contains an insecure temporary file vulnerability in bccgethostcert. The utility creates predictable temporary files without first setting a restrictive umask. A local user on the BoKS Master who can read files under BOKS_tmp may be able to obtain CA secret or host private-key material while the utility runs, or obtain CA secret material left behind after successful certificate creation.
- CVSS V3.1: AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N
- CWE: CWE-377
- Affected: New affected value received. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/79xxx/CVE-2026-79899.json">CVE-2026-79899</a>