Breaking
SecurityDeveloping Story

Fortra BoKS Patches Fix Critical Auth Bypass

Fortra fixed eight bugs in BoKS, including a 9.9-severity auth bypass and a 9.1 command injection, but reported no known exploitation.

··3 hours ago·3 min read
black and white electronic device
Photo by Elimende Inagella on Unsplash

Administrators running Fortra's Core Privileged Access Manager, known as BoKS, have eight patches to apply after the vendor disclosed flaws that include an authentication bypass rated 9.9 on the CVSS scale and a command injection rated 9.1. The company said it has seen no indication that any of the bugs have been exploited, but the affected components handle privileged access across Unix and Linux fleets, so the fixes land in code that matters.

Details were published alongside the patches, and the company pointed readers to its product security page for the full set.

What BoKS Actually Does

BoKS gives organizations central management of Unix and Linux fleets. It enforces policy and controls access across accounts, according to Fortra. That role puts it between administrators and the systems they manage.

Eight vulnerabilities were resolved in the release. Three carry critical severity, and the remaining five fall into high- and medium-severity territory. Fortra described the lower-severity group as heap buffer overflows, an out-of-bounds read, an insecure temporary file, and predictable password generation.

The 9.9 Authentication Bypass

The most severe issue, tracked as CVE-2026-79901, affects BoKS Manager deployments that rely on BoKS keytab for Active Directory service account management. Fortra assigned it a CVSS score of 9.9.

The root cause is password generation. AD service account passwords, per the advisory, are produced from a "predictable pseudo-random sequence seeded with the current Unix timestamp." That predictability is what turns a design weakness into an authentication bypass.

Fortra warned that an attacker who knows the service principal and can estimate the password-change time can reproduce a limited candidate set and verify candidates offline.

"An attacker who knows the service principal and can estimate the password-change time can reproduce a limited candidate set and verify candidates offline."

— Fortra, in its advisory on the BoKS flaws

The company laid out three conditions for exploitation: knowledge of the affected service principal, a workable estimate of when the password changed, and suitable Kerberos ticket material. A standard authenticated Active Directory account can ordinarily request a service ticket for an SPN assigned to the affected account, Fortra said. Administrative access to BoKS, the service host, or its keytab is not normally required. A previously captured service ticket can also serve as offline verification material.

Command Injection in crlserver

The second critical flaw, CVE-2026-79898, carries a CVSS score of 9.1. It is a command injection defect in crlserver. According to Fortra, an authenticated user could substitute shell commands that would be processed as root on the BoKS Master.

The advisory states the vulnerability is exploitable through BCC and the WSI REST or SOAP API. BCC and WSI can be reached over the network without a local sudo or suexec rule, Fortra said.

Stack Overflow in Autoregistration

Fortra also resolved CVE-2026-12627, a stack buffer overflow in BoKS's autoregistration functionality. It carries a CVSS score of 9.8. A remote attacker could trigger memory corruption through the flaw, per the company's description.

The Remaining Five Flaws

Beyond the three critical bugs, Fortra patched five issues across high and medium severity. They are heap buffer overflows, an out-of-bounds read, an insecure temporary file, and predictable password generation.

The source material does not list individual CVSS scores or separate CVE identifiers for those five.

What the Numbers Show

The advisory includes several figures worth keeping straight when assessing exposure:

  • Eight total vulnerabilities patched in Core Privileged Access Manager (BoKS).
  • Three of those rated critical severity.
  • Authentication bypass: CVE-2026-79901, CVSS 9.9.
  • Command injection in crlserver: CVE-2026-79898, CVSS 9.1.
  • Stack buffer overflow in autoregistration: CVE-2026-12627, CVSS 9.8.
  • Five additional high- and medium-severity flaws, including heap buffer overflows, out-of-bounds read, insecure temporary file, and predictable password generation.

No Exploitation Reported

Fortra makes no mention of any of these vulnerabilities being exploited in the wild. That is the extent of what the advisory says on the matter. Additional information can be found on Fortra's product security page, which the company cited in its disclosure.

Why It Matters for BoKS Users

The flaws sit in components that govern authentication and command handling in a privileged access manager. The authentication bypass requires only a standard authenticated Active Directory account under the conditions described, which could mean that credentials that already exist in an environment are enough to begin testing the flaw. Whether that matters depends on whether a given deployment uses BoKS keytab for AD service account management, the configuration Fortra tied to CVE-2026-79901. For organizations in that group, the fix is available now, and reviewing the advisory details is the natural next step.

#fortra#boks#vulnerability#authentication bypass#privileged access#patches

Sources

Iliyas

Founder & Editor, Xploitwire

This article was written and reviewed against the sources listed above before publication, under editorial policies set by Iliyas. Read our Editorial Policy →

← Back to all stories