Skip to main content
HIGH Vulnerabilities #Authentication Bypass

Fortra BoKS Patches Critical Vulnerabilities: RCE, Auth Bypass

4 min read Runtime Rebel Intel
Primary source: securityweek.com

This article was written by a language model from the source above and was not reviewed by a human before publication. Verify anything operational against the original. Editorial policy

Key points
  • Critical vulnerabilities in Fortra BoKS Manager could allow authentication bypass, root command execution, or memory corruption.
  • Affected systems include BoKS Manager deployments utilizing BoKS keytab for Active Directory service account management, and BoKS Master installations.
  • Organizations must apply the latest Fortra patches immediately to secure their Unix and Linux fleet management.

Advertisement

Fortra has released critical patches for eight vulnerabilities affecting its Core Privileged Access Manager (BoKS) product, which is widely used for centralized management of Unix and Linux fleets. These flaws, including three rated critical by the vendor, pose significant risks to organizations reliant on BoKS for policy enforcement and access control. While Fortra has not indicated any in-the-wild exploitation, the severity and potential impact necessitate immediate action.

Technical Details and Impact Analysis

Among the vulnerabilities addressed, three stand out due to their critical nature:

CVE-2026-79901: Authentication Bypass in BoKS Manager

Tracked as CVE-2026-79901 with a CVSS score of 9.9, this critical flaw impacts BoKS Manager deployments configured to use BoKS keytab for Active Directory service account management. The vulnerability stems from the generation of AD service account passwords using a “predictable pseudo-random sequence seeded with the current Unix timestamp.” According to Fortra, an attacker possessing knowledge of the service principal, an estimate of the password-change time, and suitable Kerberos ticket material could reproduce a limited set of password candidates for offline verification. This could lead to an authentication bypass, granting unauthorized access. A standard authenticated Active Directory account can typically request a service ticket for an SPN assigned to the affected account, meaning administrative access to BoKS or its keytab is not usually required for this attack path, as detailed by SecurityWeek.

CVE-2026-79898: Command Injection in crlserver

The second critical vulnerability, CVE-2026-79898 (CVSS 9.1), is a command injection defect found in crlserver. This flaw could allow an authenticated user to inject and execute arbitrary shell commands with root privileges on the BoKS Master. Exploitation is possible through the BoKS Client Console (BCC) and the Web Services Interface (WSI) REST or SOAP API. Critically, both BCC and WSI can be accessed over the network, eliminating the need for local sudo or suexec rules and significantly broadening the attack surface. This vulnerability represents a direct path to full system compromise of the BoKS Master.

CVE-2026-12627: Remote Memory Corruption in Autoregistration

Fortra also patched CVE-2026-12627 (CVSS 9.8), a stack buffer overflow bug present in BoKS’s autoregistration functionality. This vulnerability could be leveraged by a remote attacker to trigger memory corruption, potentially leading to denial of service or arbitrary code execution, though the source material primarily specifies memory corruption.

In addition to these critical issues, Fortra resolved five other high- and medium-severity flaws, including heap buffer overflows, an out-of-bounds read, an insecure temporary file issue, and another instance of predictable password generation.

Actionable Recommendations and Mitigation

Organizations using Fortra BoKS must prioritize patching to mitigate these severe risks. The potential for authentication bypass and root-level command injection makes these vulnerabilities highly attractive targets for malicious actors.

  • Immediate Patching: The foremost recommendation is to apply all available patches from Fortra for BoKS Core Privileged Access Manager without delay. This is crucial for addressing the Fortra BoKS critical vulnerabilities patch guidance.
  • Review Active Directory Integration: For deployments leveraging BoKS keytab with Active Directory, a thorough review of service principal names and password management practices is advised. Understanding CVE-2026-79901 authentication bypass mitigation strategies, beyond just patching, can help reduce risk.
  • Network Segmentation: Isolate BoKS Master and Manager components on a segmented network to limit exposure to the BCC and WSI interfaces, reducing the likelihood of remote exploitation.
  • Monitoring and Auditing: Implement enhanced logging and monitoring for suspicious activities related to BoKS Manager, crlserver, and autoregistration functions. Pay particular attention to authentication attempts and command execution logs. Adhering to BoKS Manager security update guidance also includes vigilance against post-patching anomalous behavior.

Related: CVE-2026-82329: JFrog Artifactory Auth Bypass to Admin Tokens, BeyondTrust RS/PRA Critical Authentication Bypass Flaws Addressed

Advertisement

Advertisement