VYPR

BoKS

by Fortra

CVEs (2)

  • CVE-2026-79901CriOct 1, 2026
    risk 0.64cvss 9.9epss —

    In deployments using BoKS keytab management, affected versions of boks_keytabmd generate Active Directory service-account passwords from a predictable pseudo-random sequence seeded with the current Unix timestamp. An attacker who knows the service principal and can estimate the…

  • CVE-2026-79899HigOct 1, 2026
    risk 0.51cvss 7.9epss —

    Fortra BoKS Manager contains an insecure temporary file vulnerability in bccgethostcert. The utility creates predictable temporary files without first setting a restrictive umask. A local user on the BoKS Master who can read files under BOKS_tmp may be able to obtain CA secret…