Fortra BoKS update fixes three critical vulnerabilities
Fortra has fixed eight security flaws in Core Privileged Access Manager, better known as BoKS. Three of them are rated critical, including an authentication bypass tied to how the product generates Active Directory service account passwords.
BoKS gives organizations a central way to manage Unix and Linux fleets. Administrators use it to enforce policies and control access across accounts, which makes it a high-value target if something goes wrong.
Predictable passwords open the door
The most severe issue is tracked as CVE-2026-79901 and carries a CVSS score of 9.9. Fortra disclosed it on Thursday, warning that it affects BoKS Manager deployments that rely on BoKS keytab to manage Active Directory service accounts. A keytab is a file that stores credentials so services can authenticate without a person typing a password.
The root cause is password generation. According to Fortra, the passwords for these AD service accounts come from a "predictable pseudo-random sequence seeded with the current Unix timestamp." In practice, the randomness depends on the time the password was set.
"An attacker who knows the service principal and can estimate the password-change time can reproduce a limited candidate set and verify candidates offline," the company explained.
To pull this off, an attacker needs three things: knowledge of the affected service principal, a reasonable estimate of when the password was changed, and suitable Kerberos ticket material. Kerberos is the authentication protocol used by Active Directory.
That last requirement is not as hard to meet as it sounds. Fortra noted that "a standard authenticated Active Directory account can ordinarily request a service ticket for an SPN assigned to the affected account; administrative access to BoKS, the service host, or its keytab is not normally required." An SPN, or service principal name, identifies a service in Active Directory. The company added that a service ticket captured earlier can also serve as material for offline verification.
Root command injection and a stack overflow
The second critical flaw, CVE-2026-79898 (CVSS score of 9.1), is a command injection bug in crlserver. An authenticated user could slip in shell commands that the BoKS Master then runs as root.
Fortra said the flaw can be reached through BCC and through the WSI REST or SOAP API. Both BCC and WSI are accessible over the network, and neither requires a local sudo or suexec rule to use. That widens the set of people who could potentially reach the vulnerable code.
The third critical bug is CVE-2026-12627, scored 9.8. It is a stack buffer overflow in the autoregistration feature of BoKS. A remote attacker could use it to trigger memory corruption.
Five more flaws fixed
Beyond the three critical issues, the update covers five vulnerabilities rated high or medium severity. These include:
- heap buffer overflows
- an out-of-bounds read
- an insecure temporary file
- predictable password generation
Fortra has not said that any of the eight flaws are being exploited in the wild. More details are available on the company's product security page.
Why It Matters
The authentication bypass is the flaw that stands out. Privileged access management tools exist to protect the most sensitive accounts in an organization, so a weakness in how such a tool creates passwords cuts against its core purpose. Because a regular authenticated AD account can usually request the ticket material needed, the barrier to abuse appears relatively low once an attacker has any foothold in the domain. The offline nature of the attack also suggests that defenders may see little noise while candidates are being tested.
The root command injection in crlserver adds to that concern, since it is reachable over the network through BCC and WSI. Network-reachable injection bugs in management products have been a recurring theme lately, as seen with the critical Fireware OS code injection flaw WatchGuard fixed last week and Dell's max severity CSM flaws that enabled admin takeover.
There is no sign of exploitation so far, but that status can change. Recent cases such as the TeamCity flaw now used by ransomware gangs show how quickly patched bugs can become attack tools once details are public. Organizations running BoKS, especially those using keytab for AD service accounts, would be wise to apply the updates soon. It is also worth considering whether affected service account passwords should be rotated after patching, since passwords generated before the fix may still follow the predictable pattern. It is worth watching whether Fortra publishes further guidance on that point, and whether researchers release technical write-ups that could speed up attacker interest.
