Vulnerability
Published 2026-10-01
Verified 2026-10-03

Fortra BoKS (1 Oct): three Criticals — CVE-2026-79901 CVSS 9.9 predictable AD keytab passwords; CVE-2026-12627 9.8 unauth autoregister overflow; CVE-2026-79898 9.1 crlserver root RCE — patch 8.1.0.24 / 9.0.0.7

Fortra Product Security published a 1 October 2026 BoKS (Core Privileged Access Manager) advisory batch covering eight flaws, three Critical. CVE-2026-79901 (FI-2026-012; CVSS 3.1 9.9; AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H): in deployments using BoKS keytab management, boks_keytabmd generates Active Directory service-account passwords from a predictable PRNG seeded with the current Unix timestamp — an attacker who knows the SPN and can estimate password-change time can reproduce a limited candidate set and verify offline (standard AD account can request a service ticket; admin access to BoKS/host/keytab not normally required). Fix: upgrade active BoKS Master to boks-server 9.0.0.7, restart BoKS, then rotate all affected/uncertain service-account passwords via BoKS keytab management and rebuild keytabs after max service-ticket lifetime + clock skew — installing the update alone does not secure passwords generated by an affected release. CVE-2026-12627 (FI-2026-017; CVSS 9.8; AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H): stack buffer overflow in boks_autoregisterd — remote attacker with network access to the autoregistration service (default port 6507) may trigger memory corruption; affected boks-server 8.1.0.0–8.1.0.23 and 9.0.0.0–9.0.0.6; fixed 8.1.0.24 / 9.0.0.7; workaround restrict/disable autoregistration until patched. CVE-2026-79898 (FI-2026-015; CVSS 9.1; AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H): authenticated command injection in crlserver via BCC / WSI REST or SOAP / cacrl — shell commands run as root on the BoKS Master; same fixed builds. Also patched: CVE-2026-79896 (High 7.5) unauth boks_portmux TLS ClientHello OOB read DoS, plus further High/Medium heap/OOB/temp-file/password issues. Fortra has not reported exploitation in the wild. Primary: Fortra FI-2026-017 / FI-2026-012 / FI-2026-015; wire: SecurityWeek 3 Oct.

Product
Fortra Core Privileged Access Manager (BoKS) / BoKS Manager (boks-server); keytab management, autoregistration, crlserver
Versions
Criticals: boks-server 8.1.0.0–8.1.0.23 and 9.0.0.0–9.0.0.6 (12627/79898); keytab flaw (79901) affects BoKS keytab→AD service-account deployments prior to 9.0.0.7. Fixed: 8.1.0.24 / 9.0.0.7. Also see FI-2026-015 (79898) and FI-2026-016 (79896 High).
CVSS
Exploited in Australia?
unknown
Patch to
Upgrade BoKS Master boks-server to 8.1.0.24 or 9.0.0.7 per Fortra FI-2026-017/015/012. For CVE-2026-79901 keytab deployments: after upgrade/restart, rotate all affected or uncertain AD service-account passwords through BoKS keytab management, confirm new key version distribution, then rebuild keytabs after max service-ticket lifetime + clock skew. Until 12627 is patched: restrict or disable network access to boks_autoregisterd (default TCP 6507).

Primary: Fortra FI-2026-017 — BoKS boks_autoregisterd stack overflow CVE-2026-12627 (1 Oct 2026) · Vendor: Fortra FI-2026-012 — BoKS keytab predictable AD passwords CVE-2026-79901 (CVSS 9.9) · CVE: CVE-2026-79901, CVE-2026-12627, CVE-2026-79898, CVE-2026-79896 · SecurityWeek — Fortra patches critical BoKS vulnerabilities (3 Oct 2026)

vulnerabilities identity network cloud