SB2026100622 - Multiple vulnerabilities in Fortra Core Privileged Access Manager (BoKS)
Published: October 6, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 7 vulnerabilities.
1) Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) (CVE-ID: CVE-2026-79901)
CWE-ID: CWE-338 - Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to compromise Active Directory service accounts.
The vulnerability exists due to use of a cryptographically weak pseudo-random number generator in boks_keytabmd when generating Active Directory service-account passwords through BoKS keytab management. A remote user can reproduce password candidates from a limited set and verify them offline to compromise Active Directory service accounts.
Exploitation requires knowledge of the service principal, an estimate of the password-change time, and suitable Kerberos ticket material.
2) Insecure Temporary File (CVE-ID: CVE-2026-79899)
CWE-ID: CWE-377 - Insecure Temporary File
CVSSv4: 8.3 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to disclose CA secret or host private-key material.
The vulnerability exists due to insecure temporary file creation in bccgethostcert when creating certificate-related temporary files. A local user can read predictable temporary files in BOKS_tmp to disclose CA secret or host private-key material.
User interaction is required.
3) OS Command Injection (CVE-ID: CVE-2026-79898)
CWE-ID: CWE-78 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to execute arbitrary commands as root.
The vulnerability exists due to improper neutralization of special elements used in an OS command in crlserver when processing CRL URLs. A remote privileged user can add a CRL URL containing shell command substitution through BCC, the WSI REST or SOAP API, or the cacrl command-line interface to execute arbitrary commands as root.
BCC and WSI provide network-accessible administration paths.
4) Out-of-bounds read (CVE-ID: CVE-2026-79896)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to an out-of-bounds read in the custom TLS ClientHello parser used by boks_portmux when processing a malformed TLS ClientHello. A remote attacker can submit a malformed ClientHello to cause a denial of service.
Repeated requests can sustain the service interruption.
5) Stack-based buffer overflow (CVE-ID: CVE-2026-12627)
CWE-ID: CWE-121 - Stack-based buffer overflow
CVSSv4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to a stack-based buffer overflow in boks_autoregisterd when processing client responses through the autoregistration service. A remote attacker can trigger memory corruption to execute arbitrary code.
6) Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) (CVE-ID: CVE-2026-9864)
CWE-ID: CWE-338 - Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)
CVSSv4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to predict machine-account passwords.
The vulnerability exists due to use of a cryptographically weak pseudo-random number generator in the adjoin utility when generating machine-account passwords during Active Directory join or password renewal operations. A remote attacker can estimate when a password was generated to predict machine-account passwords.
7) Heap-based buffer overflow (CVE-ID: CVE-2026-14316)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.3 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to a heap-based buffer overflow in boks_sshd revoked-key error handling when processing a revoked key. A remote attacker can trigger the revoked-key error path to execute arbitrary code.
User interaction is required.
Remediation
Install update from vendor's website.
References
- https://www.fortra.com/security/advisories/product-security/fi-2026-012
- https://www.fortra.com/security/advisories/product-security/fi-2026-014
- https://www.fortra.com/security/advisories/product-security/fi-2026-015
- https://www.fortra.com/security/advisories/product-security/fi-2026-016
- https://www.fortra.com/security/advisories/product-security/fi-2026-017
- https://www.fortra.com/security/advisories/product-security/fi-2026-018
- https://www.fortra.com/security/advisories/product-security/fi-2026-019