Cybersecurity Firm Fortra Patches Critical Vulnerabilities in BoKS
Fortra has released patches for eight vulnerabilities in its Core Privileged Access Manager (BoKS) software, including three critical-severity bugs that could allow attackers to bypass authentication and execute malicious commands as root on the system. The vulnerabilities affect organizations using BoKS to manage their Unix and Linux fleets and enforce policy enforcement and access control.
At the heart of two of these critical flaws is a predictable pseudo-random sequence used to generate passwords for Active Directory service accounts. This means that an attacker who knows the service principal, can estimate the password-change time, and has suitable Kerberos ticket material could potentially reproduce the password offline. Fortra warns that this information can be obtained through various means, including previously captured service tickets.
One of these critical bugs, tracked as CVE-2026-79901 (CVSS score 9.9), exists in BoKS Manager deployments relying on the keytab for Active Directory service account management. An attacker could exploit this flaw by requesting a service ticket for an SPN assigned to the affected account without requiring administrative access to BoKS or its keytab.
Another critical bug, CVE-2026-79898 (CVSS score 9.1), is a command injection defect in the crlserver that allows an authenticated user to substitute shell commands processed as root on the BoKS Master. This vulnerability can be exploited through BCC and the WSI REST or SOAP API, which can be accessed over the network without requiring local privileges.
In addition to these critical flaws, Fortra also patched five high- and medium-severity BoKS vulnerabilities, including a stack buffer overflow in autoregistration functionality that could allow remote attackers to trigger memory corruption. While there is no mention of any exploitation in the wild, organizations using BoKS should take immediate action to apply the available patches.
The widespread use of predictable pseudo-random sequences for password generation highlights the ongoing struggle with secure password management in enterprise environments. This vulnerability underscores the importance of implementing robust security measures, including regular updates and monitoring, to protect against potential attacks.
In practical terms, users of Fortra’s BoKS software should prioritize patching these vulnerabilities as soon as possible. It is also essential for organizations to review their password generation practices and consider more secure alternatives to prevent similar issues in the future. By taking proactive steps to address these vulnerabilities, organizations can significantly reduce their exposure to potential attacks and maintain a robust security posture.
Source: SecurityWeek — 2026-10-03