Skip to content

Security1 publisher2 min readPublished

Attackers who know a target's service principal can rebuild BoKS-minted AD passwords offline

Fortra patched CVE-2026-79901, a CVSS 9.9 BoKS keytab flaw that lets any authenticated Active Directory user rebuild Unix service-account passwords offline. Patching replaces the generator, but passwords it already minted stay predictable until rotated.

The Watch · Security desk

Illustration accompanying Attackers who know a target's service principal can rebuild BoKS-minted AD passwords offline
Generated illustration

What happened

  • The third, CVE-2026-12627, is a stack buffer overflow in BoKS autoregistration that a remote attacker can use to corrupt memory.
  • Fortra's release patches eight BoKS vulnerabilities in all, three of them rated critical severity.
  • Fortra reported no evidence that any of the eight flaws has been exploited in the wild.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • exposure The precondition is an ordinary directory account, so the exposed population is every authenticated AD user, not only BoKS or host administrators.
  • decision Teams that patch still have to rotate every AD service-account credential BoKS keytab produced, or the predictable passwords outlive the fix.
  • constraint BoKS is the control plane for Unix and Linux privilege, so a compromise here reaches the access system itself, not a single host.

BoKS keytab derives Active Directory service-account passwords from a pseudo-random sequence seeded with the current Unix timestamp, so the output is a function of when the password was set [4]. An attacker who knows the service principal name and can estimate when the password last changed narrows the field to a small candidate set [5]. Fortra said such an attacker "can reproduce a limited candidate set and verify candidates offline" [5].

The verification runs offline, against Kerberos ticket material rather than the account's login. The material is cheap to get. "A standard authenticated Active Directory account can ordinarily request a service ticket for an SPN assigned to the affected account; administrative access to BoKS, the service host, or its keytab is not normally required," Fortra said [7]. A ticket captured earlier works just as well [7].

In the usual version of this attack, someone who captures a service ticket still has to crack a strong password. Here the password is weak by construction, because the key space is a narrow span of timestamps [4].

Patching replaces the generator. It does not re-roll the passwords the old generator already produced, so any service-account credential BoKS keytab minted before the fix stays reproducible until it is changed [1].

The second critical bug is CVE-2026-79898, CVSS 9.1, a command injection in crlserver that lets an authenticated user run shell commands as root on the BoKS Master [8]. It is reachable over the network through BCC and the WSI REST or SOAP API, and Fortra said neither needs a local sudo or suexec rule [9]. CVE-2026-12627, CVSS 9.8, is a stack buffer overflow in autoregistration that a remote attacker can use to corrupt memory [10].

Fortra patched eight BoKS flaws in all, the three criticals plus five rated high or medium, among them more heap overflows, an out-of-bounds read, an insecure temporary file, and another predictable password generator [1][11]. The company did not report any exploitation of the eight [12].

What to watch

  • Whether proof-of-concept code or a candidate-password generator for CVE-2026-79901 appears publicly.
  • Whether CISA adds any of the three critical BoKS CVEs to its Known Exploited Vulnerabilities catalog.
  • Any Fortra guidance on rotating the AD service-account credentials BoKS keytab already minted.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories