Fortra Releases Security Patches to Address Critical BoKS Vulnerabilities

www.news4hackers.com-fortra-releases-security-patches-to-address-critical-boks-vulnerabilities-fortra-releases-security-patches-to-address-critical-boks-vulnerabilities

Fortra has addressed multiple security flaws in its Core Privileged Access Manager (BoKS) platform, including three high-severity vulnerabilities that could enable unauthorized access and system compromise.

Vulnerabilities Addressed

The updates target critical weaknesses in BoKS Manager, which is designed to manage Unix and Linux environments by enforcing access policies and controlling user permissions. The patched vulnerabilities include issues related to authentication mechanisms, command execution, and memory management.

CVE-2026-79901 (CVSS score 9.9)

A critical flaw tracked as CVE-2026-79901 (CVSS score 9.9) affects BoKS deployments that use BoKS keytab for Active Directory (AD) service account management. The vulnerability arises from the use of a predictable pseudo-random sequence to generate AD service account passwords, which are seeded with the current Unix timestamp. Attackers with knowledge of the service principal and an estimated password-change time could generate a limited set of potential passwords and validate them offline using Kerberos tickets. Fortra noted that this flaw does not require administrative access to BoKS, the service host, or its keytab, as a previously captured service ticket could provide the necessary verification material.

CVE-2026-79898 (CVSS score 9.1)

Another critical vulnerability, CVE-2026-79898 (CVSS score 9.1), involves a command injection flaw in the crlserver component of BoKS. This defect allows an authenticated user to execute arbitrary shell commands with root privileges on the BoKS Master server. The exploit is accessible via BCC and the WSI REST or SOAP API, which can be triggered over the network without requiring local sudo or suexec rules.

CVE-2026-12627 (CVSS score 9.8)

A third critical issue, CVE-2026-12627 (CVSS score 9.8), is a stack buffer overflow in BoKS’s autoregistration feature. This flaw could enable a remote attacker to trigger memory corruption, potentially leading to system instability or unauthorized code execution.

In addition to the critical vulnerabilities, Fortra resolved five high- and medium-severity flaws, including heap buffer overflows, out-of-bounds read operations, insecure temporary file handling, and predictable password generation. The company has not reported any evidence of these vulnerabilities being exploited in active attacks. The updates are available through Fortra’s product security resources. The patched components include BoKS Manager, crlserver, and autoregistration functionalities. Organizations using BoKS are advised to apply the latest updates to mitigate risks associated with these flaws. The release follows recent disclosures of other critical vulnerabilities in cybersecurity tools, highlighting ongoing efforts to address security gaps in privileged access management systems. No specific threat actor activity linked to these BoKS flaws has been reported to date.



About Author

en_USEnglish