CVE-2025-13532: medium-severity vulnerability in Fortra Core Privileged Access Manager (BoKS)
Weak Password Hash in Core Privileged Access Manager (BoKS)
Published
13Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 6.2epss 0.1%
exploitation probability
0.1%top 99% of all CVEs
observed exploitation
nono source reports it
Insecure defaults in the Server Agent component of Fortra's Core Privileged Access Manager (BoKS) can result in the selection of weak password hash algorithms. This issue affects BoKS Server Agent 9.0 instances that support yescrypt and are running in a BoKS 8.1 domain.
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Affected products
Fortra · Core Privileged Access Manager (BoKS)Related CVEs — Fortra Core Privileged Access Manager (BoKS)
In the same product, most dangerous first.
CVE-2026-9862CRITICALCore Privileged Access Manager (BoKS) autoregistration service command injection vulnerabilityEPSS 1.5%CVE-2026-9863HIGHCore Privileged Access Manager (BoKS) upgrade tooling command injection vulnerabilityEPSS 1.0%CVE-2026-14316HIGHHeap buffer overflow in boks_sshd revoked-key error handlingEPSS 0.2%CVE-2026-9864MEDIUMFortra BoKS Server Agent adjoin machine-account password generation vulnerabilityEPSS 0.1%CVE-2025-5141MEDIUMCore Privileged Access Manager (BoKS) Leakage of Sensitive Data via the CacheEPSS 0.1%