Fortra Fixes Three Critical BoKS Flaws, Five More Bugs
Fortra has patched a batch of eight vulnerabilities in its Core Privileged Access Manager (BoKS) product, three of which are rated critical and could allow an attacker to bypass authentication, execute shell commands as root on the BoKS Master, or trigger remote memory corruption. BoKS is widely deployed to centrally manage Unix and Linux account access and enforce privileged-access policy across enterprise server fleets, making the BoKS Master itself a high-value target — a successful exploit chain against any of the critical bugs could hand an attacker control over the very system that governs privileged access everywhere else. Fortra disclosed the flaws alongside patches on October 1, 2026, and says it has found no evidence of in-the-wild exploitation; no public proof-of-concept code has surfaced for the critical issues as of publication.
Vulnerability Details
| Attribute | Detail |
|---|---|
| Vendor / Product | Fortra — Core Privileged Access Manager (BoKS) |
| Total vulnerabilities patched | 8 (3 critical, 5 high/medium) |
| Most severe CVE | CVE-2026-79901 — CVSS 9.9 (authentication bypass) |
| Affected versions | BoKS Manager ≥8.1.0.0, ≤8.1.0.23 and ≥9.0.0.0, ≤9.0.0.6 |
| Patch released | October 1, 2026 |
| Exploited in the wild | No — Fortra reports no confirmed exploitation; no public PoC for the critical bugs |
| Advisories | FI-2026-007 (crlserver), FI-2026-016 (boks_portmux), FI-2026-017 (boks_autoregisterd), plus additional advisories on Fortra's product security page |
Critical Severity
| CVE | CVSS | Component | Flaw Type |
|---|---|---|---|
| CVE-2026-79901 | 9.9 | BoKS keytab / AD service account management | Authentication bypass via predictable password generation |
| CVE-2026-12627 | 9.8 | boks_autoregisterd | Remote, unauthenticated stack buffer overflow |
| CVE-2026-79898 | 9.1 | crlserver | OS command injection → root shell execution |
High / Medium Severity
| CVE | CVSS | Component | Flaw Type |
|---|---|---|---|
| CVE-2026-79899 | 7.9 | bccgethostcert | Insecure temporary file — CA secret / private-key exposure |
| CVE-2026-79896 | 7.5 | boks_portmux | Out-of-bounds read in TLS ClientHello parser (DoS) |
| Three additional CVEs | High/Medium | Unspecified | Heap buffer overflows and a second predictable password-generation issue (full CVE identifiers not individually broken out in public reporting at time of writing) |
How the Flaws Work
Authentication Bypass via Predictable AD Passwords (CVE-2026-79901)
The most severe bug, carrying a near-maximum CVSS score of 9.9, affects BoKS Manager deployments that rely on the BoKS keytab feature to manage Active Directory service account passwords. Fortra's advisory states that these passwords "are generated from a predictable pseudo-random sequence seeded with the current Unix timestamp." Because the seed is time-based rather than cryptographically random, an attacker who knows the targeted service principal name (SPN) and can estimate roughly when the password last rotated can reconstruct a small candidate set of possible passwords and verify them offline. Notably, Fortra's advisory points out that administrative access to BoKS is not required to pull this off — any standard authenticated Active Directory account can request a service ticket for the SPN assigned to the affected service account, and a previously captured service ticket alone can supply the material needed for offline password verification.
Root Command Injection in crlserver (CVE-2026-79898)
Rated 9.1, this flaw lives in crlserver, the BoKS component responsible for processing Certificate Revocation List (CRL) URLs. An authenticated user with permission to add CRL URLs — whether through the BCC console, the WSI REST or SOAP API, or the cacrl command-line utility — can smuggle shell metacharacters into a CRL URL field. crlserver fails to sanitize this input before passing it to a shell, letting the attacker-supplied command substitution execute as root on the BoKS Master. Because both BCC and WSI are reachable over the network without any local sudo or suexec rule in place, this is exploitable by any authenticated user who can reach those interfaces remotely — a low bar for an attacker who has already obtained even a low-privilege BoKS account.
Remote Buffer Overflow in Autoregistration (CVE-2026-12627)
The third critical flaw, CVSS 9.8, is a stack-based buffer overflow in boks_autoregisterd, the daemon that handles client autoregistration requests. Unlike the other two critical bugs, this one requires no authentication at all — a remote attacker can trigger memory corruption simply by sending crafted client responses to the autoregistration service, with the potential to escalate to arbitrary code execution on the BoKS Master. Because boks_autoregisterd is designed to be network-reachable (that is the point of autoregistration), this flaw gives an unauthenticated network attacker the most direct path to full compromise of any bug in the batch.
Supporting Issues: Temp Files and a Denial-of-Service Parser Bug
Two of the high-severity bugs round out the disclosure. CVE-2026-79899 (CVSS 7.9) is an insecure temporary file weakness in bccgethostcert: the utility creates predictable temp files without first applying a restrictive umask, which could let a local user who can read files under BOKS_tmp capture CA secret material or a host's private key while the utility is running. CVE-2026-79896 (CVSS 7.5) is an out-of-bounds read in the custom TLS ClientHello parser inside boks_portmux — a remote, unauthenticated attacker can submit a malformed ClientHello to crash the daemon. boks_portmux is normally auto-restarted, but repeated malformed requests can sustain a denial-of-service condition against BoKS Master connectivity.
Impact Assessment
| Impact Area | Description |
|---|---|
| Full Master compromise | Chaining the autoregistration buffer overflow (unauthenticated) with the crlserver command injection (authenticated) could give an attacker root on the system that governs privileged access for an entire Unix/Linux fleet |
| Credential theft at scale | A bypassed AD service account effectively undermines BoKS's own Active Directory trust relationship, letting an attacker impersonate the service without ever touching BoKS credentials directly |
| Blast radius | BoKS Master typically sits at the center of an organization's privileged-access architecture — compromise there cascades to every managed Unix/Linux endpoint under its policy control |
| Low attacker bar for two of three critical bugs | The buffer overflow requires no authentication, and the command injection only requires a low-privilege authenticated account with CRL-management rights reachable over BCC or WSI |
| Secondary data exposure | The insecure temp-file bug can leak CA secrets or host private keys to any local user who can read BOKS_tmp, independent of the three critical flaws |
| Availability risk | The TLS parser bug gives an unauthenticated attacker a repeatable, low-effort way to disrupt BoKS Master connectivity even without achieving code execution |
Recommendations
For BoKS Administrators
- Apply Fortra's October 1, 2026 patches to all affected BoKS Manager installations immediately — affected versions span ≥8.1.0.0 through ≤8.1.0.23 and ≥9.0.0.0 through ≤9.0.0.6; confirm your current build against Fortra's advisory portal (My Fortra) before assuming you're current
- If your deployment uses BoKS keytab for Active Directory service account management, rotate affected service account passwords after patching — the predictable-seed flaw means pre-existing passwords may already be guessable
- Audit who holds permission to add CRL URLs via BCC, WSI, or
cacrl, and tighten that permission set to the minimum necessary set of administrators - Verify network exposure of BCC, WSI, and
boks_autoregisterd— none of these should be reachable from untrusted network segments, andboks_autoregisterdin particular should be firewalled to only the hosts that legitimately need to autoregister
For Security Teams
- Treat the BoKS Master as Tier-0 infrastructure in your privileged-access model: monitor it with the same scrutiny as a domain controller, since compromise there grants effective control over every Unix/Linux endpoint it manages
- Hunt retroactively for anomalous CRL URL additions in BCC/WSI audit logs and unexpected autoregistration requests against
boks_autoregisterd, particularly any that preceded the October 1 patch availability - Review file permissions and recent access history under
BOKS_tmpfor signs that CA secret or host private-key material may already have been exposed via the insecure temp-file issue - Confirm
boks_portmuxauto-restart behavior and alerting are working correctly, since the TLS parser bug can otherwise produce a quiet, repeated service-interruption pattern that's easy to miss
For Organizations Running Legacy BoKS Builds
- This disclosure follows an earlier Fortra BoKS patch round in June 2026 (CVE-2026-9862, also in
boks_autoregisterd) that produced the s-8.1.0.23 and s-9.0.0.5 fixed releases — those June-patched builds are themselves within the version range affected by this new round, so applying the June fix alone is not sufficient - Prioritize patching if BoKS Manager is internet-facing or reachable from any network segment outside a tightly controlled management VLAN
Key Takeaways
- Fortra patched 8 vulnerabilities in Core Privileged Access Manager (BoKS) on October 1, 2026, three of them critical with CVSS scores of 9.9, 9.8, and 9.1.
- The most severe flaw, CVE-2026-79901 (9.9), is an authentication bypass caused by AD service account passwords generated from a predictable, timestamp-seeded sequence — exploitable without BoKS admin access.
- CVE-2026-12627 (9.8) is a remote, unauthenticated stack buffer overflow in
boks_autoregisterdthat can lead to memory corruption and potential code execution — the lowest bar to exploit of the three critical bugs. - CVE-2026-79898 (9.1) lets an authenticated user with CRL-management rights inject shell commands that execute as root on the BoKS Master via
crlserver. - Two additional high-severity bugs (insecure temp files exposing CA/private-key material, and a TLS parser denial-of-service flaw) round out the disclosure alongside three further unspecified high/medium issues.
- Fortra reports no known exploitation and no public proof-of-concept code exists yet, but because BoKS Master sits at the center of an organization's privileged-access architecture, patching should be treated as urgent rather than routine.