Skip to content

Image: securityweek.com · rights & removal

Executive Summary

Fortra released patches for eight vulnerabilities in Core Privileged Access Manager (BoKS), including three critical-severity bugs. One critical flaw, tracked as CVE-2026-79901 (CVSS 9.9), affects BoKS Manager deployments relying on the keytab for Active Directory service account management, potentially allowing authentication bypass by enabling offline password verification using predictable sequences seeded by Unix timestamps. A second critical bug, CVE-2026-79898 (CVSS 9.1), is a command injection defect in crlserver allowing authenticated users to substitute shell commands processed as root on the BoKS Master via BCC or WSI APIs. Additionally, a stack buffer overflow in autoregistration functionality (CVE-2026-12627, CVSS 9.8) and five other high- and medium-severity flaws involving heap buffer overflows, out-of-bounds reads, insecure temporary files, and predictable password generation were also addressed by Fortra.

Facts Only

* Fortra released patches for eight vulnerabilities in Core Privileged Access Manager (BoKS).
* Three of these vulnerabilities are critical severity bugs.
* A flaw in BoKS Manager deployments relying on the keytab for Active Directory service account management leads to authentication bypass (CVE-2026-79901, CVSS 9.9).
* The vulnerability arises because AD service account passwords are generated from a predictable pseudo-random sequence seeded with the current Unix timestamp.
* An attacker can reproduce candidate sets and verify candidates offline if they know the service principal and can estimate the password-change time, provided they have suitable Kerberos ticket material.
* A command injection defect exists in crlserver (CVE-2026-79898, CVSS 9.1) allowing an authenticated user to substitute shell commands processed as root on the BoKS Master.
* Exploitation of CVE-2026-79898 is possible through BCC and WSI REST or SOAP API over the network.
* A stack buffer overflow in BoKS’s autoregistration functionality exists (CVE-2026-12627, CVSS 9.8), allowing remote memory corruption.
* Five other high- and medium-severity BoKS flaws were patched: heap buffer overflows, out-of-bounds read, insecure temporary file, and predictable password generation.
* No mention was made of these vulnerabilities being exploited in the wild.

Full Take

The narrative centers on the security posture of privileged access management systems where cryptographic integrity and command execution are compromised. The exploitation of CVE-2026-79901 demonstrates a systemic failure in password entropy, linking high-level system operations (AD service accounts) directly to low-entropy, time-based randomness, which undermines foundational trust mechanisms like Kerberos. This moves the attack surface from requiring privileged access to exploiting temporal knowledge of session states. The command injection flaw (CVE-2026-79898) shows that even authenticated network interaction protocols (BCC/WSI) can bypass privilege separation controls on critical master components, suggesting trust boundaries enforced by software are brittle when operating over the network. The pattern observed is a focus on systemic weaknesses in key management and API security within infrastructure tooling, where predictability and access control fail simultaneously across different layers. This structure suggests that mitigating risk requires not just patching individual flaws but re-evaluating the assumptions about temporal security and least-privilege enforcement within complex enterprise management systems. What are the implicit assumptions built into current privileged access workflows that allow for the successful exploitation of time-based secrets? How do organizations reconcile the operational necessity of automated service account management with the requirement for true cryptographic unpredictability?

From the original · SecurityWeek

Fortra has released patches for eight vulnerabilities in Core Privileged Access Manager (BoKS), including three critical-severity bugs. BoKS provides organizations with central management of Unix and Linux fleets, enabling policy enforcement and access control across accounts.
Read the full story at securityweek.com

Sentinel — Human

Confidence

This text functions primarily as a factual press release detailing specific technical vulnerabilities and patches released by Fortra regarding their BoKS software, exhibiting strong characteristics of official corporate communication.

Signals Detected
low severity: Moderate sentence length variance; technical subject matter dictates slightly more dense phrasing.
low severity: Direct, factual reporting with clear cause-and-effect structure, typical of security advisories.
low severity: Structured enumeration of CVEs and associated technical details; follows a standard patch announcement format.
low severity: Absence of speculative language or sensationalism; precise attribution to the vendor (Fortra) regarding specific technical flaws.
Human Indicators
The text adopts the detached, official tone characteristic of a vendor security bulletin rather than typical journalistic narrative.
The inclusion of direct quotes from the company provides a clear source for the claims.
Fortra Patches Critical Vulnerabilities in BoKS | Huntaegis