Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-79901— Predictable Active Directory service-account passwords in BoKS Manager

Quick assessment

Affected
Fortra BoKS Manager boks-server
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在使用 BoKS keytab 管理的部署环境中,受影响的 boks_keytabmd 版本会基于当前 Unix 时间戳作为种子,从一个可预测的伪随机序列中生成 Active Directory 服务账户密码。如果攻击者知晓服务主体名称(service principal),并能估算出密码更改的时间,则可以重现一个有限的候选密码集合,并在离线环境中对这些候选项进行验证。

CVSS 9.9 · Critical

Possible ATT&CK Techniques 1 AI

T1528 · Steal Application Access Token
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-79901

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Predictable Active Directory service-account passwords in BoKS Manager
Source: CVE Program / CVE List V5
Vulnerability Description
In deployments using BoKS keytab management, affected versions of boks_keytabmd generate Active Directory service-account passwords from a predictable pseudo-random sequence seeded with the current Unix timestamp. An attacker who knows the service principal and can estimate the password-change time can reproduce a limited candidate set and verify candidates offline.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
使用具有密码学弱点缺陷的PRNG
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Fortra BoKS Manager boks-server 0 ~ 9.0.0.6 -

II. Public POCs for CVE-2026-79901

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-79901

请登录查看更多情报信息。

Other References for CVE-2026-79901 (1)

Same Patch Batch · Fortra · 2026-10-01 · 8 CVEs total

CVE-2026-12627 9.8 CRITICAL Fortra's Core Privileged Access Manager (BoKS) autoregistration stack buffer overflow vuln
CVE-2026-79898 9.1 CRITICAL Fortra BoKS Manager crlserver command injection vulnerability
CVE-2026-14316 8.1 HIGH Heap buffer overflow in boks_sshd revoked-key error handling
CVE-2026-79899 7.9 HIGH Fortra BoKS Manager bccgethostcert insecure temporary file vulnerability
CVE-2026-79896 7.5 HIGH Fortra BoKS Manager boks_portmux TLS ClientHello out-of-bounds read vulnerability
CVE-2026-79900 6.5 MEDIUM Heap overflow in KSL checksum initialization
CVE-2026-9864 4.8 MEDIUM Fortra BoKS Server Agent adjoin machine-account password generation vulnerability

IV. Related Vulnerabilities

V. Comments for CVE-2026-79901

No comments yet


Leave a comment