VYPR
patchPublished Oct 3, 2026· 1 source

Fortra Patches Critical Vulnerabilities in BoKS Privileged Access Management

Fortra has released patches for eight vulnerabilities in its Core Privileged Access Manager (BoKS), including three critical flaws that could lead to authentication bypass and command injection.

Fortra has issued urgent security updates for its Core Privileged Access Manager (BoKS) solution, addressing a total of eight vulnerabilities. Among these are three critical-severity flaws that pose a significant risk to organizations relying on BoKS for managing privileged access across Unix and Linux environments.

BoKS is designed to provide centralized management of Unix and Linux fleets, enforcing policies and controlling access to accounts. The vulnerabilities discovered could allow attackers to bypass authentication mechanisms, execute arbitrary shell commands with elevated privileges, and potentially cause memory corruption, undermining the security posture of systems that depend on BoKS for robust access control.

One of the most severe issues, tracked as CVE-2026-79901 with a CVSS score of 9.9, is a critical authentication bypass vulnerability. This flaw affects BoKS Manager deployments that use the BoKS keytab for Active Directory service account management. The vulnerability arises from the predictable pseudo-random sequence used to generate AD service account passwords, which is seeded with the current Unix timestamp. An attacker who knows the service principal and can estimate the password change time can potentially reproduce a limited set of password candidates and verify them offline.

Exploiting CVE-2026-79901 requires an attacker to know the affected service principal, estimate the password change time, and possess suitable Kerberos ticket material. Fortra noted that a standard authenticated Active Directory account can typically request a service ticket for the affected service principal name (SPN) without requiring administrative access to BoKS, the service host, or its keytab. Alternatively, a previously captured service ticket can provide the necessary offline verification material.

A second critical vulnerability, CVE-2026-79898 (CVSS score 9.1), is a command injection defect within the crlserver component. This flaw could permit an authenticated user to substitute shell commands that would then be processed with root privileges on the BoKS Master. Fortra indicated that this vulnerability is exploitable through the BCC interface and the WSI REST or SOAP API, both of which can be accessed over the network without requiring local sudo or suexec rules.

The third critical vulnerability, CVE-2026-12627 (CVSS score 9.8), is a stack buffer overflow in BoKS’s autoregistration functionality. A remote attacker could exploit this flaw to trigger memory corruption, potentially leading to denial-of-service or further compromise of the affected system.

In addition to these critical flaws, Fortra also addressed five high- and medium-severity vulnerabilities. These include heap buffer overflows, an out-of-bounds read, an insecure temporary file vulnerability, and another instance of predictable password generation. These issues, while not rated as critical, still present risks that organizations should mitigate promptly.

Fortra has not reported any instances of these vulnerabilities being exploited in the wild. The company has released patches and urges customers to update their BoKS installations as soon as possible to protect against potential attacks. Further technical details and guidance can be found on Fortra’s product security page.

Synthesized by Vypr AI