Predictable Password Generation in BoKS Keytab Management by Fortra
CVE-2026-79901

9.9CRITICAL

Key Information:

Vendor

Fortra

Vendor
CVE Published:
1 October 2026

What is CVE-2026-79901?

The vulnerability in Fortra's BoKS keytab management arises from the generation of Active Directory service-account passwords using a predictable pseudo-random sequence, which is seeded with the current Unix timestamp. This flaw allows attackers who are aware of the service principal and can estimate when the password is likely to change to recreate potential password candidates. As a result, they can verify these candidates offline, compromising the integrity of the security setup and presenting significant risks to sensitive data and systems.

Affected Version(s)

BoKS Manager boks-server 0 < 9.0.0.6

References

CVSS V3.1

Score:
9.9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.