CVE-2026-79901: Predictable BoKS service-account password generation
TL;DR - CVE-2026-79901 affects Fortra BoKS
boks_keytabmd, which can generate predictable Active Directory service-account passwords. - Exact affected and fixed versions are not published in the retrieved NVD data; obtain Fortra advisory FI-2026-012 directly. - No verified public PoC or confirmed in-the-wild exploitation was identified, but exposed credentials should be rotated promptly.
Summary
CVE-2026-79901 is a critical-severity vulnerability in the boks_keytabmd keytab-management component of Fortra BoKS. The component reportedly generates Active Directory service-account passwords using a pseudo-random sequence seeded with the current Unix timestamp. An attacker who knows the relevant service principal and can estimate the password-change time may reproduce candidate passwords and validate them offline.
The available NVD research identifies a CVSS score of 9.9 but does not provide the CVSS vector. The attack vector, privileges required, user interaction, scope, and confidentiality, integrity, and availability impact components therefore cannot be stated independently without risking an invented interpretation.
| Field | Current information |
|---|---|
| CVE ID | CVE-2026-79901 |
| Product | Fortra BoKS |
| Affected component | boks_keytabmd |
| CVSS | 9.9 |
| CVSS vector | Not included in the retrieved NVD record |
| Attack vector | Not confirmed from available data |
| Authentication or privileges required | Not confirmed from available data |
| Patch available | No fixed version confirmed; vendor advisory exists |
| CISA KEV status | Not listed |
| Public PoC | No verified CVE-specific PoC identified |
| Confirmed active exploitation | None identified in the retrieved sources |
Treat the vulnerability as a credential-compromise issue rather than as a typical memory-safety flaw. The immediate question is whether BoKS keytab management generated or manages service-account credentials in an affected configuration.
Analyst’s Take: The missing affected-version range and CVSS vector limit what can be concluded from public records, but they do not eliminate the need to investigate. Start with deployments using
boks_keytabmd, identify the service accounts they manage, and rotate credentials that may have been generated through the affected path.
Root Cause
The reported root cause is predictable credential generation in boks_keytabmd. Instead of using a cryptographically secure source of randomness, the component uses a pseudo-random sequence seeded with the current Unix timestamp. Timestamps are predictable, and password-generation events often occur within an operationally constrained window, so an attacker may be able to generate a limited set of candidate passwords.
The attack does not necessarily require repeated online authentication attempts. The vulnerability description indicates that candidates can be validated offline, although the available material does not specify the exact validation mechanism or required artifacts. If an attacker obtains the service principal, learns or estimates the password-change time, and can reproduce the generator’s behavior, the resulting credential may provide access under the service account’s Active Directory permissions.
This design creates risk even when the service account has a long password or is not directly exposed to the internet. Password complexity does not compensate for a predictable generation process. The practical impact depends on the account’s delegated rights, accessible systems, service principal configuration, and whether the account’s password or keytab material has subsequently been rotated.
Who’s Exposed
The specifically identified product is Fortra BoKS, with exposure tied to the boks_keytabmd component used for keytab management. The available NVD record does not state a reliable affected-version range. Do not infer a version boundary from third-party summaries, package names, or search-result snippets.
Investigate BoKS installations integrated with Active Directory service accounts that use boks_keytabmd to generate or manage those accounts’ credentials. A BoKS installation without this component, or a deployment that does not use the affected password-generation path, may have a different exposure profile. Confirm that distinction against Fortra’s advisory and local configuration.
The fixed version is also not identified in the retrieved information. Fortra advisory FI-2026-012 is the authoritative source for affected-version boundaries and the vendor-recommended release, but the advisory was inaccessible to the research process because the request returned HTTP 403.
Severity Breakdown
The published CVSS score is 9.9, which places this issue in the critical range. The supplied NVD result contains no CVSS vector. Without the vector, defenders cannot reliably determine whether the score reflects a network attack vector, low or no privileges, no user interaction, or a particular impact combination.
| CVSS component | Status |
|---|---|
| Base score | 9.9 |
| Vector string | Not provided |
| Attack vector | Unknown |
| Attack complexity | Unknown |
| Privileges required | Unknown |
| User interaction | Unknown |
| Scope | Unknown |
| Confidentiality impact | Unknown |
| Integrity impact | Unknown |
| Availability impact | Unknown |
The score should influence prioritization because compromise of an Active Directory service account can create broad downstream exposure. Operational severity depends heavily on account privileges. A narrowly delegated account may limit impact, while an account used by multiple services or granted administrative rights could enable lateral movement, persistence, or access to sensitive systems.
Review service-account permissions against least-privilege principles, including role-based access control. See the RBAC glossary guide for background on reducing unnecessary authorization scope.
Do not substitute an assumed CVSS vector for the missing data. Recheck the NVD record and Fortra advisory for a later vector update before using individual CVSS metrics in risk models or automated exception workflows.
Exploitation Status
No confirmed in-the-wild exploitation of CVE-2026-79901 was identified in the retrieved sources. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. That absence means CISA has not included it in the retrieved catalog; it does not prove that exploitation has never occurred or that private exploitation is impossible.
No verified public proof-of-concept repository or exploit publication specifically associated with CVE-2026-79901 was identified. Generic CVE collection pages and broad vulnerability digests are not evidence of a CVE-specific PoC. The technical description nevertheless provides a plausible exploitation path involving timestamp estimation, candidate generation, and offline validation.
Distinguish between “no confirmed exploitation observed” and “low technical risk.” Attackers who already know BoKS deployment details, service principals, or password-change schedules may have an advantage even without a public exploit. Treat suspicious authentication involving affected principals as potentially significant until the account is rotated and the activity is explained.
Sources
The primary sources are the NVD record for CVE-2026-79901 and Fortra’s security advisory FI-2026-012. The NVD material supplies the CVE identifier, product and component context, CVSS score, and vulnerability description. It does not supply the affected-version range, fixed version, or CVSS vector in the retrieved data.
Fortra’s advisory should be treated as authoritative for release boundaries, upgrade instructions, workarounds, and any vendor-specific detection guidance:
The advisory returned HTTP 403 during retrieval for this assessment. Administrators should access it directly through Fortra’s website or support channel and update internal records when the affected and fixed versions are confirmed. No verified public PoC, confirmed exploitation report, or CVE-specific GitHub reference was identified in the available research.
This article may contain affiliate links. We earn a commission on qualifying purchases at no extra cost to you.
Detection Guidance
Start by identifying BoKS systems that use boks_keytabmd, the Active Directory service principals they manage, and the last known password-change or keytab-generation times. The available material does not provide a vendor-specific log format, event ID, network signature, or detection rule. Detection should combine configuration inventory with identity-provider telemetry.
Review Active Directory authentication events for affected service accounts. Look for unusual source hosts, new geographic locations, interactive logons, access outside the account’s normal service schedule, and authentication shortly after a suspected password-generation event. Depending on the environment, useful Windows events include successful and failed logon records such as 4624 and 4625, Kerberos service-ticket events such as 4769, and account-password changes such as 4723 or 4724. Event availability and field meanings depend on audit policy and domain configuration.
Technical Notes
A starting point for Microsoft Sentinel or another Kusto-compatible platform is:
let affectedAccounts = dynamic(["svc_example", "svc_boks"]);
SecurityEvent
| where EventID in (4624, 4625, 4769)
| where Account has_any (affectedAccounts)
| project TimeGenerated, EventID, Account, Computer, IpAddress,
LogonType, AuthenticationPackageName, Status, Activity
| order by TimeGenerated desc
Replace the example account list with the actual service principals identified during inventory. Alert on source systems that have not previously used the account, interactive logon types inconsistent with service operation, repeated failures followed by success, and ticket requests from unexpected hosts. This query is a triage pattern, not a CVE-specific signature.
Remediation Steps
First, obtain Fortra security advisory FI-2026-012 directly and confirm the affected-version range and fixed release. The retrieved research does not establish either value, so it is not safe to claim that a particular BoKS version resolves the issue. After the vendor confirms the fixed version, upgrade every affected boks_keytabmd deployment according to Fortra’s supported procedure and verify the installed component version.
Rotate credentials for Active Directory service accounts whose passwords may have been generated or managed by the affected component. Use the organization’s approved AD process, update dependent services and keytabs, and verify that old credentials no longer authenticate. If the account is highly privileged or cannot be confidently scoped, treat it as potentially compromised and follow the organization’s incident-response process.
Until the fixed release is confirmed and deployed, consider disabling or removing the affected password-generation workflow where operationally feasible. Do not rely on password complexity, a firewall boundary, or the absence of CISA KEV listing as a substitute for remediation. Review account delegation, remove unnecessary privileges, restrict logon rights, and ensure service accounts cannot perform interactive logons where that is compatible with application requirements.
For human administrator credentials involved in the response, use an approved enterprise password manager such as 1Password rather than storing recovery credentials in scripts, tickets, or shared documents. Do not place Active Directory service-account passwords in an external password manager unless that process is explicitly approved by your organization’s security policy.
Technical Notes
A controlled password reset for a known AD service account can be performed with an approved administrative PowerShell session:
Import-Module ActiveDirectory
$account = "svc_boks_example"
$newPassword = Read-Host "Enter a new randomly generated password" -AsSecureString
Set-ADAccountPassword `
-Identity $account `
-Reset `
-NewPassword $newPassword
Set-ADUser -Identity $account -ChangePasswordAtLogon $false
This command resets the directory password but does not automatically update every application, keytab, secret store, or service that depends on the account. Coordinate the reset with the BoKS and application owners, regenerate or replace keytabs using the vendor-supported process, restart dependent services where required, and test Kerberos authentication. Do not place passwords directly in shell history or source code.
For the product upgrade itself, use the exact package, installer, or repository command documented by Fortra for the confirmed fixed release. No reliable upgrade command or fixed version was available in the retrieved material, so inventing one could damage a production BoKS deployment.
After credential rotation and patching, document the affected accounts, systems, keytabs, reset times, validation results, and any authentication anomalies. If suspicious activity was identified, conduct a formal post-incident review using a structured post-incident review guide.