Build1 publisher2 min readPublished
Fortra's BoKS lets an attacker rederive AD service-account passwords offline
Fortra disclosed eight vulnerabilities in its BoKS privileged-access manager, three of them critical and one rated CVSS 9.9. Because the predictable passwords can be verified offline, applying the fix does not retire service-account credentials an attacker may already hold.
The Engineer · Build desk
Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

What happened
- The predictable passwords derive from timestamp seeds, so an attacker builds a short candidate list and checks each one offline against captured Kerberos material.
- The offline check needs only a standard authenticated AD account or previously captured ticket material, not BoKS administration, service-host rights, or keytab access.
- The documentation Fortra reviewed reports no active exploitation and no public proof-of-concept code for any of the eight flaws.
Compiled by The EngineerSomething wrong?How this is made
Why it matters
- decision Closing this takes two steps, applying the update and rotating affected service-account passwords and keytabs, because the credentials already in AD were made by the weak generator.
- constraint The guessing runs on the attacker's hardware, so the Master logs nothing and defenders cannot confirm from logs whether a password was already derived.
- exposure Any BoKS user who can add a CRL URL effectively holds root on the Master, so the privileged-access tool's own lower-tier admins become a path to full control.
- capability An unauthenticated attacker gains a repeatable way to keep BoKS authentication offline by repeating requests, even though stable code execution for CVE-2026-12627 is unproven.
The password candidates come from timestamp seeds [8]. An attacker who knows roughly when a service account last rotated can build a short list of likely passwords and test each one offline against captured Kerberos material [8]. That test needs a standard authenticated AD account to request a service ticket, or ticket material grabbed earlier. It does not need BoKS administration rights, service-host rights, or keytab access [9]. A correct guess authenticates as the service account [10].
This is why the update does not close the exposure on its own. Fixing the generator changes how new passwords are produced. The passwords already in Active Directory were produced the old, predictable way. Fortra's remediation for FI-2026-012 therefore includes password and keytab updates, not just a software patch [14][6]. Closing it is two steps: apply the update, then rotate the affected service accounts and their keytabs.
The guessing happens off your systems. The BoKS Master never processes the candidates, so there is nothing in its logs to say whether someone already derived a password [8]. Fortra flags the limits of offline verification when trying to determine compromise [14].
Path B is the root command injection, CVE-2026-79898 [3]. An authenticated BoKS user with rights to add CRL URLs reaches the BCC or WSI REST/SOAP APIs over the network and registers a value containing shell command substitution [11]. When crlserver processes that value, the embedded command runs as root on the BoKS Master, and local sudo or suexec rules do not have to allow it [11].
Path C needs no credentials at all. An attacker who can reach boks_autoregisterd or boks_portmux over the network sends oversized input in an autoregistration response to trigger stack corruption, or a malformed TLS ClientHello to terminate boks_portmux [12][4]. The process usually restarts by itself, which helps right up until the attacker asks again; repeated requests keep the service down [13]. Whether CVE-2026-12627 can be driven to stable code execution cannot be determined from public information [13].
For detection, Fortra lists shell processes spawned by crlserver, modified CRL URLs, repeated boks_portmux restarts, unknown autoregistration or TLS connections, and odd Kerberos authentication events for AD service accounts [15]. Check Manager and Server Agent versions separately before deciding you are covered [16]; the flaws span BoKS Manager, the Server Agent, and Fortra Core Privileged Access Manager [7]. The documentation Fortra reviewed reports no active exploitation and no public proof-of-concept code [5].
What to watch
- Whether a public proof-of-concept for CVE-2026-12627 appears, which would settle if the pre-auth bug reaches code execution or stays a denial of service.
- Fortra's per-CVE affected-version table pinning exactly which BoKS Manager and Server Agent builds need the update.
- Any reports of active exploitation, which the reviewed documentation currently says there are none of.