CVE-2026-79899

Fortra BoKS Manager enthält eine Schwachstelle durch unsichere temporäre Dateien in bccgethostcert.

Description

Fortra BoKS Manager contains an insecure temporary file vulnerability in bccgethostcert. The utility creates predictable temporary files without first setting a restrictive umask. A local user on the BoKS Master who can read files under BOKS_tmp may be able to obtain CA secret or host private-key material while the utility runs, or obtain CA secret material left behind after successful certificate creation.

Metrics

7.9
Source: cna-v3
0.1 %
Low — this CVE sits in the lower 10% of all CVEs scored today.
Show all metrics
Severity
high
no public PoC known
0.1 %
Low — model estimates < 1% exploitation likelihood.
Published
2026-10-01 14:37 UTC
CWE-377

Weakness classes (CWE)

  • CWE-377Class

    Insecure Temporary File

    Creating and using insecure temporary files can leave application and system data vulnerable to attack.

    cwe.mitre.org →

References & sources

Reanalysis & status changes

Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.

  1. CVE Modified2026-10-01 16:18 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
    • SSVC: {"id":"CVE-2026-79899","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalI…
  2. New CVE Received2026-10-01 15:17 UTC· df4dee71-de3a-4139-9588-11b62fe6c0ff
    • Description: Fortra BoKS Manager contains an insecure temporary file vulnerability in bccgethostcert. The utility creates predictable temporary files without first setting a restrictive umask. A local user on the BoKS Master who can read files under BOKS_tmp may be able to obtain CA secret or host private-key material while the utility runs, or obtain CA secret material left behind after successful certificate creation.
    • CVSS V3.1: AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N
    • CWE: CWE-377
    • Affected: New affected value received. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/79xxx/CVE-2026-79899.json">CVE-2026-79899</a>