FORTRA has issued patches addressing eight vulnerabilities in its Core Privileged Access Manager (BoKS), including three rated as critical. The most severe, CVE-2026-79901 (CVSS 9.9), affects BoKS Manager deployments that use BoKS keytabs for Active Directory service account management. The flaw arises because AD service account passwords are generated from a predictable pseudo-random sequence seeded with the current Unix timestamp.
An attacker who knows the service principal and can estimate the password-change time could reconstruct a limited set of candidate passwords and verify them offline. Fortra notes that an attacker would need to know the affected service principal, have an estimated password-change time, and possess suitable Kerberos ticket material; a standard authenticated AD account can ordinarily request a service ticket for the SPN, and a previously captured service ticket could provide offline verification material.
The second critical issue, CVE-2026-79898 (CVSS 9.1), is a command-injection vulnerability in crlserver that could let an authenticated user substitute shell commands executed as root on the BoKS Master. The flaw is exploitable via BCC and the WSI REST or SOAP API, which are network-accessible without requiring local sudo or suEXEC rules. A third high-severity flaw, CVE-2026-12627 (CVSS 9.8), is a stack buffer overflow in BoKS’s autoregistration function that could enable remote memory corruption.
In addition, Fortra patched five other high- and medium-severity issues (heap/buffer overflows, out-of-bounds read, insecure temporary files, and predictable password generation). The company states that there is no evidence of exploitation in the wild to date.