Fortra BoKS Patches Fix Critical Auth Bypass
Fortra fixed eight bugs in BoKS, including a 9.9-severity auth bypass and a 9.1 command injection, but reported no known exploitation.
Administrators running Fortra's Core Privileged Access Manager, known as BoKS, have eight patches to apply after the vendor disclosed flaws that include an authentication bypass rated 9.9 on the CVSS scale and a command injection rated 9.1. The company said it has seen no indication that any of the bugs have been exploited, but the affected components handle privileged access across Unix and Linux fleets, so the fixes land in code that matters.
Details were published alongside the patches, and the company pointed readers to its product security page for the full set.
What BoKS Actually Does
BoKS gives organizations central management of Unix and Linux fleets. It enforces policy and controls access across accounts, according to Fortra. That role puts it between administrators and the systems they manage.
Eight vulnerabilities were resolved in the release. Three carry critical severity, and the remaining five fall into high- and medium-severity territory. Fortra described the lower-severity group as heap buffer overflows, an out-of-bounds read, an insecure temporary file, and predictable password generation.
The 9.9 Authentication Bypass
The most severe issue, tracked as CVE-2026-79901, affects BoKS Manager deployments that rely on BoKS keytab for Active Directory service account management. Fortra assigned it a CVSS score of 9.9.
The root cause is password generation. AD service account passwords, per the advisory, are produced from a "predictable pseudo-random sequence seeded with the current Unix timestamp." That predictability is what turns a design weakness into an authentication bypass.
Fortra warned that an attacker who knows the service principal and can estimate the password-change time can reproduce a limited candidate set and verify candidates offline.
"An attacker who knows the service principal and can estimate the password-change time can reproduce a limited candidate set and verify candidates offline."
— Fortra, in its advisory on the BoKS flaws
The company laid out three conditions for exploitation: knowledge of the affected service principal, a workable estimate of when the password changed, and suitable Kerberos ticket material. A standard authenticated Active Directory account can ordinarily request a service ticket for an SPN assigned to the affected account, Fortra said. Administrative access to BoKS, the service host, or its keytab is not normally required. A previously captured service ticket can also serve as offline verification material.
Command Injection in crlserver
The second critical flaw, CVE-2026-79898, carries a CVSS score of 9.1. It is a command injection defect in crlserver. According to Fortra, an authenticated user could substitute shell commands that would be processed as root on the BoKS Master.
The advisory states the vulnerability is exploitable through BCC and the WSI REST or SOAP API. BCC and WSI can be reached over the network without a local sudo or suexec rule, Fortra said.
Stack Overflow in Autoregistration
Fortra also resolved CVE-2026-12627, a stack buffer overflow in BoKS's autoregistration functionality. It carries a CVSS score of 9.8. A remote attacker could trigger memory corruption through the flaw, per the company's description.
The Remaining Five Flaws
Beyond the three critical bugs, Fortra patched five issues across high and medium severity. They are heap buffer overflows, an out-of-bounds read, an insecure temporary file, and predictable password generation.
The source material does not list individual CVSS scores or separate CVE identifiers for those five.
What the Numbers Show
The advisory includes several figures worth keeping straight when assessing exposure:
- Eight total vulnerabilities patched in Core Privileged Access Manager (BoKS).
- Three of those rated critical severity.
- Authentication bypass: CVE-2026-79901, CVSS 9.9.
- Command injection in crlserver: CVE-2026-79898, CVSS 9.1.
- Stack buffer overflow in autoregistration: CVE-2026-12627, CVSS 9.8.
- Five additional high- and medium-severity flaws, including heap buffer overflows, out-of-bounds read, insecure temporary file, and predictable password generation.
No Exploitation Reported
Fortra makes no mention of any of these vulnerabilities being exploited in the wild. That is the extent of what the advisory says on the matter. Additional information can be found on Fortra's product security page, which the company cited in its disclosure.
Why It Matters for BoKS Users
The flaws sit in components that govern authentication and command handling in a privileged access manager. The authentication bypass requires only a standard authenticated Active Directory account under the conditions described, which could mean that credentials that already exist in an environment are enough to begin testing the flaw. Whether that matters depends on whether a given deployment uses BoKS keytab for AD service account management, the configuration Fortra tied to CVE-2026-79901. For organizations in that group, the fix is available now, and reviewing the advisory details is the natural next step.
Sources
- SecurityWeek Original source
- product security Also reporting
Continue Reading
MI5: MSS Front Funded 100+ Academics
The alert urges U.K. universities to review CGTRI ties, warning that continuing collaboration could lead to prosecution.
Sanders bill targets federal Flock use
Sen. Bernie Sanders introduced the Ban Flock Act to bar federal agencies from using license plate readers or accessing their data.
Fake Zoom Installer Delivers macOS Backdoor
Researchers at Jamf say a bogus Zoom app installs CloudSyncD, a backdoor that abuses user passwords to run with root privileges.