www.securityweek.com 3 Oct 2026, 11:34 UTC

Fortra Patches Critical BoKS Flaw Enabling AD Password Cracking

Fortra Patches Critical BoKS Flaw Enabling AD Password Cracking
CyberSIXT Evidence Panel Source marked as original reporting
CISA KEV Not in KEV
Patch Patch Status Unknown

FORTRA has issued patches addressing eight vulnerabilities in its Core Privileged Access Manager (BoKS), including three rated as critical. The most severe, CVE-2026-79901 (CVSS 9.9), affects BoKS Manager deployments that use BoKS keytabs for Active Directory service account management. The flaw arises because AD service account passwords are generated from a predictable pseudo-random sequence seeded with the current Unix timestamp.

An attacker who knows the service principal and can estimate the password-change time could reconstruct a limited set of candidate passwords and verify them offline. Fortra notes that an attacker would need to know the affected service principal, have an estimated password-change time, and possess suitable Kerberos ticket material; a standard authenticated AD account can ordinarily request a service ticket for the SPN, and a previously captured service ticket could provide offline verification material.

The second critical issue, CVE-2026-79898 (CVSS 9.1), is a command-injection vulnerability in crlserver that could let an authenticated user substitute shell commands executed as root on the BoKS Master. The flaw is exploitable via BCC and the WSI REST or SOAP API, which are network-accessible without requiring local sudo or suEXEC rules. A third high-severity flaw, CVE-2026-12627 (CVSS 9.8), is a stack buffer overflow in BoKS’s autoregistration function that could enable remote memory corruption.

In addition, Fortra patched five other high- and medium-severity issues (heap/buffer overflows, out-of-bounds read, insecure temporary files, and predictable password generation). The company states that there is no evidence of exploitation in the wild to date.

View full article

Article by CyberSIXT