๐Ÿ” CVE Alert

CVE-2026-79901

CRITICAL 9.9

Predictable Active Directory service-account passwords in BoKS Manager

CVSS Score
9.9
EPSS Score
0.0%
EPSS Percentile
0th

In deployments using BoKS keytab management, affected versions of boks_keytabmd generate Active Directory service-account passwords from a predictable pseudo-random sequence seeded with the current Unix timestamp. An attacker who knows the service principal and can estimate the password-change time can reproduce a limited candidate set and verify candidates offline.

CWE CWE-338
Vendor fortra
Product boks manager boks-server
Published Oct 1, 2026
Last Updated Oct 1, 2026
Stay Ahead of the Next One

Get instant alerts for fortra boks manager boks-server

Be the first to know when new critical vulnerabilities affecting fortra boks manager boks-server are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
High
Availability
High

Affected Versions

Fortra / BoKS Manager boks-server
0 < 9.0.0.6

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
fortra.com: https://www.fortra.com/security/advisories/product-security/fi-2026-012