Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) in Core Privileged Access Manager (BoKS) - CVE-2026-79901
Published: October 6, 2026
Vulnerability details
The vulnerability allows a remote user to compromise Active Directory service accounts.
The vulnerability exists due to use of a cryptographically weak pseudo-random number generator in boks_keytabmd when generating Active Directory service-account passwords through BoKS keytab management. A remote user can reproduce password candidates from a limited set and verify them offline to compromise Active Directory service accounts.
Exploitation requires knowledge of the service principal, an estimate of the password-change time, and suitable Kerberos ticket material.