Bypass Record

Exploitation for Priv-Esc × Fortra BoKS Core Privileged Access Manager

A publicly-reported instance of Exploitation for Priv-Esc bypassing Fortra BoKS Core Privileged Access Manager, recorded with its original source. Factual record; no assessment of any specific deployment.

Product
Fortra BoKS Core Privileged Access Manager
Technique
Exploitation for Priv-Esc
MITRE ATT&CK
T1068
Confidence
High
Severity
Critical
Status
unknown
Disclosed
2026-10-04
Config / version noted
Not stated

Provenance

Reported as

It defeats the security boundary of the privileged access manager

Mechanism

The vulnerability allows OS command injection, enabling an attacker to execute arbitrary commands on the host system. It defeats the security boundary of the privileged access manager, which is designed to control and monitor privileged access.

Detection & mitigation

Monitor for unusual command execution or process creation on systems running BoKS Core. Ensure the product is patched to the latest version and restrict access to the management interface.

Exploitation for Priv-Esc has also been recorded against

This is a record of a publicly-reported event, not an assessment of any specific organization's deployment. Detection and mitigation notes are drawn from the cited source. Where the source is silent, fields are omitted.