Fortra BoKS Server Agent 中的 adjoin 工具存在一个可预测的密码生成漏洞。在加入 Active Directory 或执行密码更新操作时生成的机器账户密码,其随机性(熵)可能远低于预期,从而更容易被能够估算密码生成时间的攻击者所预测。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Fortra | Core Privileged Access Manager (BoKS) | 8.1.0.0 ~ 8.1.0.29 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-79901 | 9.9 CRITICAL | Predictable Active Directory service-account passwords in BoKS Manager |
| CVE-2026-12627 | 9.8 CRITICAL | Fortra's Core Privileged Access Manager (BoKS) autoregistration stack buffer overflow vuln |
| CVE-2026-79898 | 9.1 CRITICAL | Fortra BoKS Manager crlserver command injection vulnerability |
| CVE-2026-14316 | 8.1 HIGH | Heap buffer overflow in boks_sshd revoked-key error handling |
| CVE-2026-79899 | 7.9 HIGH | Fortra BoKS Manager bccgethostcert insecure temporary file vulnerability |
| CVE-2026-79896 | 7.5 HIGH | Fortra BoKS Manager boks_portmux TLS ClientHello out-of-bounds read vulnerability |
| CVE-2026-79900 | 6.5 MEDIUM | Heap overflow in KSL checksum initialization |
No comments yet