Fortra patches three critical flaws in BoKS privileged access manager

Fortra fixed eight vulnerabilities in Core Privileged Access Manager (BoKS), including three critical bugs that could enable authentication bypass and root-level command execution.

Fortra patches three critical flaws in BoKS privileged access manager

At a glance

  • Fortra patched eight flaws in BoKS, three of them rated critical, SecurityWeek reported.
  • CVE-2026-79901 (CVSS 9.9) stems from AD service account passwords generated with a timestamp-seeded pseudo-random sequence.
  • CVE-2026-79898 allows authenticated command injection as root on the BoKS Master; CVE-2026-12627 is an unauthenticated stack overflow.
  • No in-the-wild exploitation has been reported; administrators should update, with boks-server 9.0.0.6 listed as fixing CVE-2026-79901.

Fortra has released patches for eight vulnerabilities in Core Privileged Access Manager, better known as BoKS, a tool used to manage access across Unix and Linux server fleets, SecurityWeek reported on October 3. Three of the flaws are rated critical and could allow attackers to bypass authentication, run shell commands as root on the central BoKS Master server or corrupt memory without authenticating. Because BoKS controls privileged access to large numbers of servers, a compromise of the management layer could have wide consequences.

What happened

According to SecurityWeek, Fortra fixed eight security defects in BoKS, three of them classified as critical and five as medium or high severity. The publication said there is no evidence that any of the vulnerabilities has been exploited in the wild. Details are published on Fortra's product security advisory page; the public CVE record for the most severe issue references Fortra advisory FI-2026-012 and lists October 1 as its publication date.

Technical details

The most severe bug, CVE-2026-79901 (CVSS 9.9), affects BoKS Manager deployments that use keytab-based management of Active Directory service accounts. SecurityWeek, citing Fortra, said the AD service account passwords are generated from a predictable pseudo-random sequence seeded with the current Unix timestamp. An attacker who knows the service principal and can estimate when the password was changed could narrow down a limited set of candidates and verify them offline using captured Kerberos tickets. The CVE record classifies the issue as CWE-338, use of a cryptographically weak pseudo-random number generator.

CVE-2026-79898 (CVSS 9.1) is a command injection flaw in the crlserver component. According to the report, it allows authenticated users to inject shell commands that are executed as root on the BoKS Master, and it can be reached over the network through the BCC and WSI REST/SOAP APIs.

CVE-2026-12627 (CVSS 9.8) is a stack buffer overflow in the autoregistration functionality that, SecurityWeek said, remote attackers can trigger without authentication to corrupt memory.

The remaining five issues include heap buffer overflows, an out-of-bounds read, insecure temporary file handling and weak password generation, according to the report.

Who is affected

Organizations running Fortra Core Privileged Access Manager (BoKS) to govern privileged access on Unix and Linux systems are affected. The CVE record for CVE-2026-79901 lists BoKS Manager boks-server versions earlier than 9.0.0.6 as vulnerable. Deployments that use keytab management for AD service accounts are specifically exposed to that flaw.

What to do

Administrators should review Fortra's advisory and apply the available updates, moving boks-server to version 9.0.0.6 or later for the password generation flaw. Until patching is complete, restricting network access to the BoKS Master and its BCC and WSI APIs, as well as to the autoregistration service, can reduce exposure. Organizations using keytab-managed AD service accounts should consider rotating those passwords after updating, since passwords generated by vulnerable versions may be predictable.

Related CVEs

Sources

This story is based on the sources listed above. Always check the vendor’s official advisory before acting on critical systems.