Skip to content
Security & Trust

Fortra patches BoKS flaws in the tool that guards Linux admin access

Three critical bugs sit in software that controls who can act as root across Unix and Linux fleets

W
WebPulse Newsroom
AI-assisted · 4 min read
Share on X LinkedIn
Fortra patches BoKS flaws in the tool that guards Linux admin access

AI-generated image for WebPulse. About our images

In brief
  • Fortra patched eight flaws in BoKS, its Unix and Linux access manager, including three critical ones. The worst, CVE-2026-79901, scores 9.9.
  • Tools that control privileged access hold the keys to many servers, so a flaw in them reaches further than one in an ordinary application.
  • Confirm whether BoKS runs in your estate and which features you use, then schedule patches. Fortra mentions no exploitation in the wild, which does not prove none has occurred.

The lock that holds the keys

A random password is only as random as its starting point. If the starting point is the clock, an attacker has a short list of guesses to try.

That is the core of one of three critical flaws Fortra has patched in Core Privileged Access Manager, known as BoKS. SecurityWeek reported the fixes on October 3, 2026. SecurityWeek describes BoKS as central management of Unix and Linux fleets. It enforces policy and controls access across accounts.

The lesson here is about where risk concentrates. A privileged access manager decides who may act as an administrator on many servers. A weakness in it is not one more bug in one more application. It sits where trust for many servers is decided.

8, including 3 critical
Vulnerabilities patched in BoKS
Source: Fortra advisory, as reported by SecurityWeek (October 3, 2026)

How a password built from the clock gets guessed

The most severe flaw is CVE-2026-79901, scored 9.9 on the CVSS severity scale. It leads to authentication bypass. It affects BoKS Manager deployments that use the BoKS keytab to manage Active Directory service accounts. A keytab is a file that stores the credentials a service uses to prove its identity.

Fortra says the passwords for those accounts come from a "predictable pseudo-random sequence seeded with the current Unix timestamp." In plain terms, the password generator starts from the time of day. If you can guess roughly when a password was changed, you can shrink the list of possible passwords a great deal.

Fortra says the attacker then checks that short list offline. The guessing runs on the attacker's own machine. The target system never sees the failed tries.

Three conditions apply. The attacker must know the service principal, which is the name of the service account. They must estimate when the password changed. And they need suitable Kerberos ticket material, the proof a domain issues when a user asks to use a service.

The entry requirement is low. Fortra says an ordinary logged-in domain account can usually request that ticket. Control of BoKS, the service host or the keytab is not normally needed. A ticket captured earlier can also be used for the offline checks.

Even so, the attack is not automatic. It still depends on the attacker knowing the service principal and estimating the password-change time.

9.9
CVE-2026-79901 severity (CVSS)
Source: Fortra advisory, as reported by SecurityWeek (October 3, 2026)

Two more paths to the same prize

CVE-2026-79898, scored 9.1, is a command injection flaw in crlserver. An authenticated user could swap in shell commands. The BoKS Master would then run them as root.

According to Fortra, an attacker would reach this flaw through BCC, or through WSI in either its REST or SOAP form. Neither route needs a local sudo or suexec rule, and both can be used across the network. Those rules normally limit who may run privileged commands.

CVE-2026-12627, scored 9.8, is a stack buffer overflow in the autoregistration feature. It could let a remote attacker trigger memory corruption. That means writing data past the space a program set aside. The result can be a crash or changed behavior.

9.8
CVE-2026-12627 severity (CVSS)
Source: Fortra advisory, as reported by SecurityWeek (October 3, 2026)

Fortra also fixed five high- and medium-severity flaws. They include heap buffer overflows, an out-of-bounds read, an insecure temporary file and a second case of predictable password generation.

What is known and what is not

Fortra makes no mention of any of these flaws being exploited in the wild. That is silence, not proof. It is a fair starting point for planning, but not a reason to wait.

The SecurityWeek report gives no affected or fixed version numbers. Teams should take those from Fortra's product security page, not from a summary.

Questions to put to your team

First, do we run BoKS, and which parts? The password flaw applies to deployments that use the BoKS keytab for Active Directory service accounts. Confirm whether ours do.

Second, who can reach BCC and the WSI API over the network? Fortra says no local sudo or suexec rule is needed to reach them. Network access is therefore the control that remains. Teams can narrow it before a patch window opens.

Third, when were the affected service account passwords last changed? Fortra says an attacker must estimate that time. Ask whether the patch also calls for rotating those passwords, and check Fortra's guidance.

Privileged access software earns its place by being the most trusted system in the estate. That also makes it the first place a patch plan should look.

Produced by the WebPulse Newsroom with AI assistance from the original reporting credited below, and checked against that source by our editorial review. How we use AI.
Original reporting: SecurityWeek.

Share this insight