Predictable Password Generation Vulnerability in Fortra BoKS Server Agent
CVE-2026-9864

4.8MEDIUM

Key Information:

Vendor

Fortra

Vendor
CVE Published:
1 October 2026

What is CVE-2026-9864?

The Fortra BoKS Server Agent contains a vulnerability in its adjoin utility, where machine-account passwords generated during Active Directory join or renewal operations may exhibit significantly reduced entropy. This reduction in randomness heightens the risk of these passwords being predicted by attackers, particularly if they can estimate the time of generation. As a result, effective countermeasures should be considered to mitigate the potential for unauthorized access stemming from this vulnerability.

Affected Version(s)

Core Privileged Access Manager (BoKS) 8.1.0.0 <= 8.1.0.29

Core Privileged Access Manager (BoKS) 9.0.0.0 <= 9.0.0.5

References

CVSS V3.1

Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.