Fortra BoKS: Predictable AD Passwords, Root Command Injection, and Pre-Authentication Memory Corruption
1. Basic Information Original Title: Predictable Active Directory service-account passwords in BoKS Manager Source: Fortra Published Date: 2026-10-01 Updated Date: 2026-10-01 Report Revision Reason: Technical review:
1. Basic Information
- Original Title: Predictable Active Directory service-account passwords in BoKS Manager
- Source: Fortra
- Published Date: 2026-10-01
- Updated Date: 2026-10-01
- Report Revision Reason: Technical review: Changed the primary source to FI-2026-012 and corrected CVE-specific affected versions and updates based on Fortra CNA, password/keytab updates, compromise determination and offline verification limits, and ATT&CK mappings.
- Severity: Critical
- Severity Basis: Three vulnerabilities are rated critical, including CVE-2026-79901 with a CVSS v3.1 score of 9.9, CVE-2026-79898 allowing root command execution by authenticated users with CRL URL addition rights, and CVE-2026-12627 leading to pre-authentication remote memory corruption. Official documentation reviewed contains no reports of active exploitation or public PoCs.
- Source Reference: Fortra FI-2026-012
- Related Sources: SecurityWeek, FI-2026-013, FI-2026-014, FI-2026-015, FI-2026-016, FI-2026-017, FI-2026-018, FI-2026-019, Canadian Centre for Cyber Security AV26-987, Fortra CNA: CVE-2026-79901, Fortra CNA: CVE-2026-79900, Fortra CNA: CVE-2026-79899, Fortra CNA: CVE-2026-79898, Fortra CNA: CVE-2026-79896, Fortra CNA: CVE-2026-12627, Fortra CNA: CVE-2026-9864, Fortra CNA: CVE-2026-14316, MITRE ATT&CK: Unix Shell
- Related Malware: None
- Related Threat Groups: None
- Related CVEs: CVE-2026-79901, CVE-2026-79900, CVE-2026-79899, CVE-2026-79898, CVE-2026-79896, CVE-2026-12627, CVE-2026-9864, CVE-2026-14316
- Affected Products: Fortra Core Privileged Access Manager (BoKS), BoKS Manager, BoKS Server Agent
2. Executive Summary
The eight vulnerabilities in Fortra Core Privileged Access Manager (BoKS) include predictable generation of AD service-account passwords, command injection through CRL URLs that can execute commands as root on the BoKS Master, and a pre-authentication stack buffer overflow in the autoregistration service.
3. Attack Flow
Flow 1: Path A: Predictable Active Directory Service Account Passwords
- Paths A, B, and C represent independent vulnerability vectors. In Path A, the attacker identifies an affected BoKS keytab management configuration, a service principal, and the approximate time range of a password change.
- The attacker either uses a standard authenticated AD account to request a service ticket for the target SPN or uses previously obtained ticket material for offline verification. BoKS administration rights, service-host administration rights, and keytab access are not normally required.
- A limited set of password candidates is derived from timestamp seeds and validated offline using Kerberos material. Obtaining the correct candidate may allow authentication as the target service account.
Flow 2: Path B: Root Command Execution on BoKS Master via CRL URL
- The attacker obtains authenticated privileges to add CRL URLs and reaches the BCC or WSI REST/SOAP APIs over the network.
- The attacker registers a value containing shell command substitution into a CRL URL.
- When crlserver processes the value, the embedded command is executed as root on the BoKS Master.
Flow 3: Path C: Pre-Authentication Memory Corruption or Persistent Denial of Service
- The attacker reaches boks_autoregisterd or boks_portmux over the network.
- Sending oversized input in an autoregistration client response triggers a stack memory corruption. Alternatively, a malformed TLS ClientHello terminates boks_portmux.
- While boks_portmux typically restarts automatically, repeating requests maintains service interruption. Stable code execution conditions for CVE-2026-12627 cannot be determined from public information alone.
4. Attacker Positioning and Execution Location
- Path A requires an attacker with a standard authenticated AD account capable of obtaining a service ticket for the target SPN, or an attacker possessing previously acquired ticket material.
- Path B requires an authenticated BoKS user with permission to add CRL URLs. BCC and WSI are accessible over the network, and local sudo/suexec rules are not required.
- Path C involves an unauthenticated remote attacker with network reachability to the autoregistration service or boks_portmux.
5. Indicators for Victims and Administrators
Victims
- During service outages, symptoms may manifest as failures in Unix/Linux management functions or related authentication and operational processes. No real-world examples have been published.
Administrators
- Indicators include unknown autoregistration/TLS connections from unfamiliar sources, repeated restarts of boks_portmux, modified CRL URLs, shell processes spawned by crlserver, and suspicious Kerberos authentication events for AD service accounts.
6. Conditions for Success and Failure
Success Conditions
- Components matching the affected versions and configuration criteria for specific CVEs listed in the table below must be running. Verify Manager and Server Agent versions independently.
- For CVE-2026-79901, passwords generated by vulnerable BoKS keytab management configurations must be in use, alongside a service principal, an estimated password change timestamp, and Kerberos material capable of offline validation. Initial passwords assigned by administrators are excluded from this generation process.
- For CVE-2026-79898, the attacker must have CRL URL addition rights and access to BCC, WSI, or cacrl. This requires CRLS add permissions in BCC, addCACRLURL and required BCCAS permissions in WSI, or appropriate sudo/suexec rules for non-root cacrl execution.
- For CVE-2026-12627 and CVE-2026-79896, network reachability to the target daemon is required.
Failure Conditions
- Update systems according to the table below by CVE, product, and maintenance line, and ensure updated daemons are running. The CNA countermeasure for CVE-2026-79901 requires updating the active BoKS Master to boks-server 9.0.0.7, restarting BoKS, and then regenerating passwords.
- Restrict BoKS management APIs, autoregistration, and boks_portmux to management networks, and remove unnecessary CRL URL addition rights and local sudo/suexec rules. These actions do not replace software updates.
- For CVE-2026-79901, rotate passwords through BoKS keytab management for affected service accounts and accounts whose affected status is uncertain, and confirm that the new key version has been distributed. After the AD domain's configured maximum service-ticket lifetime plus clock-skew allowance has elapsed, rebuild affected keytabs during a maintenance window so that they contain only the current key version. Redistribute and verify the rebuilt keytabs, restart or reload dependent services as needed, and test Kerberos authentication. If compromise is suspected, rotate passwords and rebuild keytabs immediately rather than waiting for existing tickets to expire. Also rotate machine-account passwords affected by CVE-2026-9864 and potentially exposed CA secrets or host private keys according to the impact assessment.
Affected Versions and Updates by CVE
Scope of impact and countermeasures based on Fortra CNA records are organized by CVE. Because the upper bound for affected versions of CVE-2026-79901 (9.0.0.6) differs from the specified countermeasure version (9.0.0.7), version 9.0.0.6 is not recommended as an update target.
| CVE | Component | Impact Scope and Conditions | Countermeasure |
|---|---|---|---|
| CVE-2026-79901 | boks_keytabmd / BoKS Manager | CNA affected field: boks-server below 9.0.0.6. Passwords generated by keytab management apply. | CNA update target: 9.0.0.7. Update active Master, restart BoKS, then update passwords and keytabs. Verify individual patch levels for the 8.1 line separately. |
| CVE-2026-79900, CVE-2026-79899, CVE-2026-79898, CVE-2026-79896, CVE-2026-12627 | boks-server / BoKS Manager | 8.1 line below 8.1.0.24, 9.0 line below 9.0.0.7. KSL path requires authenticated clients, CRL path requires addition rights, temporary file path requires BOKS_tmp read permission. | Update to respective maintenance lines 8.1.0.24 / 9.0.0.7 and verify updated daemons are running. |
| CVE-2026-9864 | adjoin / BoKS Server Agent (boks-client) | Versions 8.1.0.0 through 8.1.0.29, 9.0.0.0 through 9.0.0.5. Applies to machine-account password generation during AD join and automatic password updates. | Update to boks-client patch releases newer than 8.1.0.29 / 9.0.0.5 across respective lines, then update machine-account passwords generated by affected versions. |
| CVE-2026-14316 | boks_sshd | Versions 8.1.0.0 to below 8.1.0.30, 10.1.0.0 to below 10.1.1.0. Condition requires reaching the revoked key check error path during public key authentication when RevokedKeys is configured. | CNA instruction is to update to patched versions. Verify distribution packages and maintenance line compatibility with Fortra; do not assume complete remediation for all products based solely on upper boundary versions. |
7. Impact of Successful Exploitation
- Deduction of AD service account passwords and subsequent authentication and operations using those account privileges.
- Root command execution on the BoKS Master.
- Potential impacts on confidentiality, integrity, and availability via pre-authentication memory corruption.
- Service interruption caused by repeated termination of boks_portmux.
- For CVE-2026-79899, a local user who can read files under BOKS_tmp on the BoKS Master may obtain CA secrets or host private keys while bccgethostcert is running. CA secrets left in temporary files may also remain accessible after certificate creation has completed successfully.
8. Observable Logs
- No specific email logs are associated with this issue.
Proxy / SWG / DNS
- If BCC or WSI REST/SOAP APIs transit through a proxy, review CRL URL modification requests, sources, responses, and abnormal shell metacharacters.
Endpoint / EDR
- On the BoKS Master, check for shells or utility processes parented by crlserver, crashes, core dumps, and repeated restarts of boks_portmux/boks_autoregisterd, as well as temporary file creation and reading in BOKS_tmp.
Identity / IdP
- Review Kerberos service ticket requests directed to SPNs associated with target service accounts, noting requesting accounts and hosts. Subsequent logons by target service accounts should be tracked separately. Offline validation does not require high-volume TGS requests or communication immediately following password changes.
SaaS / Cloud
- No SaaS or cloud-specific logs exist for this issue. If Active Directory is integrated with cloud monitoring, review service account sign-ins.
Network
- Inspect connection sources for the autoregistration service, boks_portmux, and BCC/WSI, along with repetitive malformed TLS sessions and traffic patterns corresponding to service restarts.
9. Attack Success Assessment
Attack Attempt Observed (Success Unconfirmed)
- Public Information and Criteria: The reviewed public sources do not report exploitation in the wild. Malformed ClientHello messages, autoregistration errors, or anomalous CRL URL values alone do not establish root command execution or successful authentication. Correlate these observations with process and identity logs.
- Target Scope: BoKS network services and management APIs
- Related CVEs: CVE-2026-79898, CVE-2026-79896, CVE-2026-12627
Malware Execution or Successful Authentication Confirmed
- Public Information and Criteria: Public information: Official documentation explains vulnerability conditions and impacts but demonstrates no real-world success instances. Criteria: Correlate malicious CRL URL processing with root execution of attacker-supplied commands, or substantiate unauthorized authentication success by target service accounts. Suspicious shells or anomalous authentication alone do not confirm successful compromise; even if unauthorized authentication is verified, additional evidence is required to confirm password derivation methods.
- Target Scope: BoKS Master and Active Directory
- Related CVEs: CVE-2026-79901, CVE-2026-79898
Subsequent Compromise Confirmed
- Public Information and Criteria: Check for file changes, account creation, credential access, or lateral movement following unauthorized root command execution. Separately, check for unauthorized operations performed using a compromised AD service account; this path does not require prior root command execution. The reviewed public sources do not describe observed cases of these follow-on activities.
- Target Scope: BoKS management domains and connected Unix/Linux/AD environments
- Related CVEs: CVE-2026-79901, CVE-2026-79898, CVE-2026-12627
10. Investigation Playbook
Trigger
- Trigger investigations upon identifying vulnerable versions, externally reachable BoKS services, repeated crashes, abnormal CRL URLs, or suspicious Kerberos authentications for service accounts.
Initial Verification
- Verify boks-server, boks-client, and boks_sshd versions and maintenance lines, keytab management and adjoin usage, RevokedKeys settings, open ports, CRL URL addition permissions, BOKS_tmp permissions, and log retention status.
Endpoints
- Preserve process trees, core dumps, service restarts, temporary files, and configuration/binary changes on the BoKS Master, and check for child processes originating from crlserver.
Identity and Cloud
- Review AD service principals, password change histories, TGS requests, service account logons, ticket validity periods, and connection sources.
Subsequent Operations
- Track account, key, and scheduled task modifications under root privileges, lateral movement to connected Unix/Linux systems, and the usage destinations of CA/host keys and service accounts.
Containment
- Isolate management interfaces and, after preserving evidence, apply the appropriate fixes for each CVE and product. Follow Section 6 to rotate service-account passwords, remove obsolete key versions by rebuilding affected keytabs, and redistribute the rebuilt keytabs. Apply the waiting period and suspected-compromise exception described there. Rotate affected machine-account passwords and potentially exposed CA secrets or host keys according to the impact assessment, and invalidate suspicious sessions.
Classification Categories
- Record observations distinguishing between reachability only, daemon crashes, root command execution, AD authentication success, credential/key exposure, and subsequent compromise.
11. Defense and Detection Ideas
Single Event
- Alert on shell metacharacters in CRL URL modification values, shell execution spawned by crlserver, crashes of boks_portmux/autoregisterd, and anomalous logons by target service accounts.
Time-Series Correlation
- Correlate management API requests -> CRL URL modifications -> crlserver child processes -> file/account modifications by root. On the AD side, track ticket requests directed to target SPNs and unauthorized service account usage, noting that offline validation using past tickets may not generate new or high-volume TGS requests.
Threat Hunting Perspectives
- Search for exposed BoKS service scopes, legacy versions, SPNs targeted by keytab management, historical CRL URL modifications, BOKS_tmp access, repeated restarts, and service account usage origins.
Log Gaps
- Raw payloads reaching vulnerable parsers or offline password validation may not be visible in endpoint or AD logs alone. Combine packet capture, reverse proxy, Kerberos, and process telemetry.
Priority Mitigations
- Prioritize applying the appropriate fixes, restricting access to management interfaces and autoregistration services, minimizing CRL URL addition privileges, and rotating affected account passwords and key material.
12. Facts / Inference / Hypothesis
Facts
- For CVE-2026-79901, boks_keytabmd generates AD service account passwords from predictable pseudorandom sequences seeded by Unix timestamps. Attackers can validate candidates offline using service principals, estimated password change timestamps, and Kerberos service ticket material.
- For CVE-2026-79898, authenticated users permitted to add CRL URLs can inject shell command substitution via BCC, WSI REST/SOAP APIs, or cacrl, causing crlserver on the BoKS Master to process them as root.
- For CVE-2026-12627, a stack-based buffer overflow occurs during client response processing in boks_autoregisterd reachable over the network, allowing unauthenticated remote attackers to trigger memory corruption.
- Additional issues include heap overflows by authenticated KSL clients, CA secret and host private key exposure via predictable temporary files, persistent denial of service via TLS ClientHello, insufficient entropy in AD machine-account passwords, and heap overflows in boks_sshd.
- According to Fortra CNA records, multiple Manager CVEs are addressed in boks-server versions 8.1.0.24 and 9.0.0.7 across respective maintenance lines. However, countermeasures for CVE-2026-79901 specify version 9.0.0.7 along with restarts and password/keytab updates, while CVE-2026-9864 requires boks-client updates and machine-account password updates. CVE-2026-14316 reflects separate impact scopes in the 8.1 and 10.1 lines, for which remediation cannot be verified solely through uniform boks-server updates.
- Reviewed Fortra advisories and CNA records contain no documentation of active exploitation in real-world environments.
Inference
- Environments exposing BoKS Masters or autoregistration services beyond management networks face increased exposure to pre-authentication memory corruption and denial of service, necessitating simultaneous updates and reachability restrictions.
- Considering risks associated with residual old keys remaining in keytabs, remediation cannot be treated as complete via password updates alone; tracking must extend through official key version removal, redistribution, and dependent service authentication verification.
Hypothesis
No additional hypotheses. Unverified items are documented in Section 14.
13. MITRE ATT&CK Mapping
| ID | Technique | Confidence | Basis |
|---|---|---|---|
| T1059.004 | Command and Scripting Interpreter: Unix Shell | high | Fortra describes the possibility of root execution via shell command substitution in CRL URLs. This maps to mechanics rather than real-world observation. |
14. Open Questions and Further Investigation
- Conditions required to escalate memory corruption in CVE-2026-12627 to stable code execution and the existence of public PoCs.
- Default listen addresses for daemons, exposure status outside management networks, and detailed audit logs for each vulnerable code path.
- The timeframe until which previously generated passwords persist in CVE-2026-79901 and how exploitation can be determined from tickets or logs.
- Specific patch levels for CVE-2026-79901 in the 8.1 line, and distribution package and maintenance line mappings for CVE-2026-14316. Verification is required to confirm whether versions outside the listed ranges are secure.
15. Impact on SOCs and Organizations
Organizations utilizing BoKS for privileged access management on Unix/Linux systems should verify the reachability scopes of BoKS Masters, autoregistration services, and boks_portmux, alongside maintenance lines for Managers and Server Agents. Following updates, evaluate service and machine account passwords, old keytab keys, CA secrets, and host private keys, executing necessary replacements, legacy key removal, and historical log reviews.
16. Summary by Role
- SOC: Correlate BoKS management APIs, autoregistration, TLS ClientHello, Kerberos service tickets, CRL URL modifications, and child processes on the BoKS Master to investigate denial of service, credential derivation, and root command execution separately.
- Administrators: Apply the updates for each affected product and maintenance line specified in Section 6, and restrict access to BoKS management interfaces and autoregistration services. Verify service-account and machine-account password rotation, removal of obsolete key versions, redistribution of rebuilt keytabs containing only current keys, and replacement of potentially exposed CA or host keys. Follow Section 6 for keytab maintenance timing and the immediate-response exception when compromise is suspected.
- Users: End-user actions are generally not required. Follow administrative guidance if notified regarding password changes or re-authentications.
Originally published by Dev.to Security. Aggregated on AIWithGhost for educational purposes β full credit and traffic to the original publisher.