A Critical Flaw Hits BoKS Manager Deployments, Leaving Organizations Exposed to Authentication Bypass Attacks
Fortra has just released patches for a severe security flaw in its Core Privileged Access Manager (BoKS) solution. The vulnerability, tracked as CVE-2026-79901, is critical in severity and affects organizations that rely on BoKS Manager deployments for Active Directory service account management.
At the heart of this issue lies a predictable pseudo-random sequence used to generate AD service account passwords. This means that an attacker who knows the affected service principal and can estimate the password-change time can reproduce a limited set of potential passwords offline, making it possible to bypass authentication controls. Fortra warns that this vulnerability is particularly concerning because it doesn’t require administrative access to BoKS or its keytab; even a standard authenticated Active Directory account could exploit it.
To make matters worse, an attacker who has captured a service ticket for the affected account can verify candidates offline using Kerberos ticket material. This makes it clear that organizations must take immediate action to patch their systems and prevent potential exploitation.
But CVE-2026-79901 is just one of several critical vulnerabilities identified in BoKS. Another high-severity bug, tracked as CVE-2026-79898, is a command injection defect in the crlserver that could allow an authenticated user to substitute shell commands processed as root on the BoKS Master. This vulnerability can be exploited through various interfaces, including BCC and WSI REST or SOAP API, which are accessible over the network without requiring local sudo or suexec rules.
Fortra has also resolved a stack buffer overflow in BoKS’s autoregistration functionality (CVE-2026-12627), allowing remote attackers to trigger memory corruption. In addition to these critical vulnerabilities, five high- and medium-severity flaws were patched: heap buffer overflows, out-of-bounds read, insecure temporary file, and predictable password generation.
While Fortra makes no mention of any exploitation in the wild, organizations relying on BoKS must act swiftly to patch their systems and prevent potential attacks. These patches are available on Fortra’s product security page for immediate download.
In practical terms, this means that IT teams should prioritize updating all affected systems with the latest patches as soon as possible. This includes ensuring that system administrators are aware of the vulnerability and take necessary precautions to mitigate its impact. Remember, timely patching is key in preventing potential exploitation; don’t wait until it’s too late to act.
Source: SecurityWeek — 2026-10-03