Zero Day Room
Live
Vulnerabilities

Fortra patches critical BoKS vulnerabilities

Fortra has released patches for eight vulnerabilities in its BoKS Privileged Access Manager, three of which are critical.

Fortra has released patches for eight vulnerabilities in its BoKS Privileged Access Manager, three of which are critical

Fortra has released patches for eight vulnerabilities in its Core Privileged Access Manager (BoKS), including three critical-severity flaws affecting authentication and command execution. The update addresses immediate risks for organizations using the platform to manage Unix and Linux fleet access control.

Authentication bypass via predictable password generation in AD-integrated deployments

A critical authentication bypass flaw, tracked as CVE-2026-79901 and scoring 9.9 on the CVSS scale, affects BoKS Manager deployments that rely on BoKS keytab for Active Directory service account management. The vulnerability exists because AD service account passwords are generated from a predictable pseudo-random sequence seeded with the current Unix timestamp. Fortra said, "An attacker who knows the service principal and can estimate the password-change time can reproduce a limited candidate set and verify candidates offline."

Exploitation is possible if an attacker knows the affected service principal, can estimate the password-change time, and has suitable Kerberos ticket material. A standard authenticated Active Directory account can ordinarily request a service ticket for the SPN assigned to the affected account. Administrative access to BoKS, the service host, or its keytab is not required. A previously captured service ticket can also provide offline verification material.

Command injection enables root-level exploitation via APIs

The second critical bug, CVE-2026-79898 with a CVSS score of 9.1, is a command injection defect in the crlserver component. It could allow an authenticated user to substitute shell commands that are then processed as root on the BoKS Master server. This flaw is exploitable through the BCC and the WSI REST or SOAP APIs. These interfaces can be accessed over the network without requiring a local sudo or suexec rule, enabling remote command execution with root privileges.

Remote code execution via autoregistration service flaw

Fortra also resolved CVE-2026-12627, a stack buffer overflow in BoKS’s autoregistration functionality, which carries a CVSS score of 9.8. The boks_autoregisterd service, which handles autoregistration of new hosts, is vulnerable due to improper input sanitization. A remote attacker could trigger memory corruption, potentially leading to unauthorized system control, data exfiltration, lateral movement, or service disruption.

The vulnerability is exploitable over the network without authentication or user interaction. Attackers can automate exploitation. Any exposed BoKS instance with the autoregistration service enabled is a potential target. Organizations should restrict network access to TCP port 6507, ensuring only trusted hosts and internal segments can communicate with the boks_autoregisterd service.

Additional high- and medium-severity flaws addressed in advisory

Beyond the critical issues, Fortra patched five additional high- and medium-severity BoKS flaws. These include heap buffer overflows, an out-of-bounds read vulnerability, an insecure temporary file handling issue, and another instance of predictable password generation. Fortra makes no mention of any of these vulnerabilities being exploited in the wild.

BoKS provides organizations with central management of Unix and Linux fleets, enabling policy enforcement and access control across accounts. Organizations should consult Fortra’s official advisory FI-2026-007 to determine affected versions, apply patches, disable the boks_autoregisterd service if not required, and increase monitoring of potentially impacted systems. Additional information can be found on Fortra’s product security page.

Related coverage

More from Vulnerabilities