Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) in Core Privileged Access Manager (BoKS) - CVE-2026-9864
Published: October 6, 2026
Vulnerability details
The vulnerability allows a remote attacker to predict machine-account passwords.
The vulnerability exists due to use of a cryptographically weak pseudo-random number generator in the adjoin utility when generating machine-account passwords during Active Directory join or password renewal operations. A remote attacker can estimate when a password was generated to predict machine-account passwords.