NEWS

Fortra Patches Critical Vulnerabilities in BoKS

Fortra fixed 8 BoKS flaws, including a 9.9 CVSS AD auth bypass, 9.1 root command injection, and 9.8 remote buffer overflow bug.

Dylan H.

News Desk

October 3, 2026
9 min read
Fortra Patches Critical Vulnerabilities in BoKS

Fortra Fixes Three Critical BoKS Flaws, Five More Bugs

Fortra has patched a batch of eight vulnerabilities in its Core Privileged Access Manager (BoKS) product, three of which are rated critical and could allow an attacker to bypass authentication, execute shell commands as root on the BoKS Master, or trigger remote memory corruption. BoKS is widely deployed to centrally manage Unix and Linux account access and enforce privileged-access policy across enterprise server fleets, making the BoKS Master itself a high-value target — a successful exploit chain against any of the critical bugs could hand an attacker control over the very system that governs privileged access everywhere else. Fortra disclosed the flaws alongside patches on October 1, 2026, and says it has found no evidence of in-the-wild exploitation; no public proof-of-concept code has surfaced for the critical issues as of publication.


Vulnerability Details

AttributeDetail
Vendor / ProductFortra — Core Privileged Access Manager (BoKS)
Total vulnerabilities patched8 (3 critical, 5 high/medium)
Most severe CVECVE-2026-79901 — CVSS 9.9 (authentication bypass)
Affected versionsBoKS Manager ≥8.1.0.0, ≤8.1.0.23 and ≥9.0.0.0, ≤9.0.0.6
Patch releasedOctober 1, 2026
Exploited in the wildNo — Fortra reports no confirmed exploitation; no public PoC for the critical bugs
AdvisoriesFI-2026-007 (crlserver), FI-2026-016 (boks_portmux), FI-2026-017 (boks_autoregisterd), plus additional advisories on Fortra's product security page

Critical Severity

CVECVSSComponentFlaw Type
CVE-2026-799019.9BoKS keytab / AD service account managementAuthentication bypass via predictable password generation
CVE-2026-126279.8boks_autoregisterdRemote, unauthenticated stack buffer overflow
CVE-2026-798989.1crlserverOS command injection → root shell execution

High / Medium Severity

CVECVSSComponentFlaw Type
CVE-2026-798997.9bccgethostcertInsecure temporary file — CA secret / private-key exposure
CVE-2026-798967.5boks_portmuxOut-of-bounds read in TLS ClientHello parser (DoS)
Three additional CVEsHigh/MediumUnspecifiedHeap buffer overflows and a second predictable password-generation issue (full CVE identifiers not individually broken out in public reporting at time of writing)

How the Flaws Work

Authentication Bypass via Predictable AD Passwords (CVE-2026-79901)

The most severe bug, carrying a near-maximum CVSS score of 9.9, affects BoKS Manager deployments that rely on the BoKS keytab feature to manage Active Directory service account passwords. Fortra's advisory states that these passwords "are generated from a predictable pseudo-random sequence seeded with the current Unix timestamp." Because the seed is time-based rather than cryptographically random, an attacker who knows the targeted service principal name (SPN) and can estimate roughly when the password last rotated can reconstruct a small candidate set of possible passwords and verify them offline. Notably, Fortra's advisory points out that administrative access to BoKS is not required to pull this off — any standard authenticated Active Directory account can request a service ticket for the SPN assigned to the affected service account, and a previously captured service ticket alone can supply the material needed for offline password verification.

Root Command Injection in crlserver (CVE-2026-79898)

Rated 9.1, this flaw lives in crlserver, the BoKS component responsible for processing Certificate Revocation List (CRL) URLs. An authenticated user with permission to add CRL URLs — whether through the BCC console, the WSI REST or SOAP API, or the cacrl command-line utility — can smuggle shell metacharacters into a CRL URL field. crlserver fails to sanitize this input before passing it to a shell, letting the attacker-supplied command substitution execute as root on the BoKS Master. Because both BCC and WSI are reachable over the network without any local sudo or suexec rule in place, this is exploitable by any authenticated user who can reach those interfaces remotely — a low bar for an attacker who has already obtained even a low-privilege BoKS account.

Remote Buffer Overflow in Autoregistration (CVE-2026-12627)

The third critical flaw, CVSS 9.8, is a stack-based buffer overflow in boks_autoregisterd, the daemon that handles client autoregistration requests. Unlike the other two critical bugs, this one requires no authentication at all — a remote attacker can trigger memory corruption simply by sending crafted client responses to the autoregistration service, with the potential to escalate to arbitrary code execution on the BoKS Master. Because boks_autoregisterd is designed to be network-reachable (that is the point of autoregistration), this flaw gives an unauthenticated network attacker the most direct path to full compromise of any bug in the batch.

Supporting Issues: Temp Files and a Denial-of-Service Parser Bug

Two of the high-severity bugs round out the disclosure. CVE-2026-79899 (CVSS 7.9) is an insecure temporary file weakness in bccgethostcert: the utility creates predictable temp files without first applying a restrictive umask, which could let a local user who can read files under BOKS_tmp capture CA secret material or a host's private key while the utility is running. CVE-2026-79896 (CVSS 7.5) is an out-of-bounds read in the custom TLS ClientHello parser inside boks_portmux — a remote, unauthenticated attacker can submit a malformed ClientHello to crash the daemon. boks_portmux is normally auto-restarted, but repeated malformed requests can sustain a denial-of-service condition against BoKS Master connectivity.


Impact Assessment

Impact AreaDescription
Full Master compromiseChaining the autoregistration buffer overflow (unauthenticated) with the crlserver command injection (authenticated) could give an attacker root on the system that governs privileged access for an entire Unix/Linux fleet
Credential theft at scaleA bypassed AD service account effectively undermines BoKS's own Active Directory trust relationship, letting an attacker impersonate the service without ever touching BoKS credentials directly
Blast radiusBoKS Master typically sits at the center of an organization's privileged-access architecture — compromise there cascades to every managed Unix/Linux endpoint under its policy control
Low attacker bar for two of three critical bugsThe buffer overflow requires no authentication, and the command injection only requires a low-privilege authenticated account with CRL-management rights reachable over BCC or WSI
Secondary data exposureThe insecure temp-file bug can leak CA secrets or host private keys to any local user who can read BOKS_tmp, independent of the three critical flaws
Availability riskThe TLS parser bug gives an unauthenticated attacker a repeatable, low-effort way to disrupt BoKS Master connectivity even without achieving code execution

Recommendations

For BoKS Administrators

  • Apply Fortra's October 1, 2026 patches to all affected BoKS Manager installations immediately — affected versions span ≥8.1.0.0 through ≤8.1.0.23 and ≥9.0.0.0 through ≤9.0.0.6; confirm your current build against Fortra's advisory portal (My Fortra) before assuming you're current
  • If your deployment uses BoKS keytab for Active Directory service account management, rotate affected service account passwords after patching — the predictable-seed flaw means pre-existing passwords may already be guessable
  • Audit who holds permission to add CRL URLs via BCC, WSI, or cacrl, and tighten that permission set to the minimum necessary set of administrators
  • Verify network exposure of BCC, WSI, and boks_autoregisterd — none of these should be reachable from untrusted network segments, and boks_autoregisterd in particular should be firewalled to only the hosts that legitimately need to autoregister

For Security Teams

  • Treat the BoKS Master as Tier-0 infrastructure in your privileged-access model: monitor it with the same scrutiny as a domain controller, since compromise there grants effective control over every Unix/Linux endpoint it manages
  • Hunt retroactively for anomalous CRL URL additions in BCC/WSI audit logs and unexpected autoregistration requests against boks_autoregisterd, particularly any that preceded the October 1 patch availability
  • Review file permissions and recent access history under BOKS_tmp for signs that CA secret or host private-key material may already have been exposed via the insecure temp-file issue
  • Confirm boks_portmux auto-restart behavior and alerting are working correctly, since the TLS parser bug can otherwise produce a quiet, repeated service-interruption pattern that's easy to miss

For Organizations Running Legacy BoKS Builds

  • This disclosure follows an earlier Fortra BoKS patch round in June 2026 (CVE-2026-9862, also in boks_autoregisterd) that produced the s-8.1.0.23 and s-9.0.0.5 fixed releases — those June-patched builds are themselves within the version range affected by this new round, so applying the June fix alone is not sufficient
  • Prioritize patching if BoKS Manager is internet-facing or reachable from any network segment outside a tightly controlled management VLAN

Key Takeaways

  1. Fortra patched 8 vulnerabilities in Core Privileged Access Manager (BoKS) on October 1, 2026, three of them critical with CVSS scores of 9.9, 9.8, and 9.1.
  2. The most severe flaw, CVE-2026-79901 (9.9), is an authentication bypass caused by AD service account passwords generated from a predictable, timestamp-seeded sequence — exploitable without BoKS admin access.
  3. CVE-2026-12627 (9.8) is a remote, unauthenticated stack buffer overflow in boks_autoregisterd that can lead to memory corruption and potential code execution — the lowest bar to exploit of the three critical bugs.
  4. CVE-2026-79898 (9.1) lets an authenticated user with CRL-management rights inject shell commands that execute as root on the BoKS Master via crlserver.
  5. Two additional high-severity bugs (insecure temp files exposing CA/private-key material, and a TLS parser denial-of-service flaw) round out the disclosure alongside three further unspecified high/medium issues.
  6. Fortra reports no known exploitation and no public proof-of-concept code exists yet, but because BoKS Master sits at the center of an organization's privileged-access architecture, patching should be treated as urgent rather than routine.

Sources