Fortra Patches Critical Vulnerabilities in BoKS
Fortra has released patches for eight vulnerabilities in Core Privileged Access Manager (BoKS), including three critical-severity bugs.
BoKS provides organizations with central management of Unix and Linux fleets, enabling policy enforcement and access control across accounts.
On Thursday, the company warned that BoKS Manager deployments relying on BoKS keytab for Active Directory service account management are affected by a critical flaw leading to authentication bypass.
Tracked as CVE-2026-79901 (CVSS score of 9.9), the issue exists because AD service account passwords are generated from a “predictable pseudo-random sequence seeded with the current Unix timestamp.”
“An attacker who knows the service principal and can estimate the password-change time can reproduce a limited candidate set and verify candidates offline,” Fortra warned.
The company underlined that an attacker could exploit the flaw if they knew the affected service principal, could estimate the password-change time, and had suitable Kerberos ticket material.
Advertisement. Scroll to continue...
Copyright of this story solely belongs to www.securityweek.com. To see the full text click HERE