Description
In deployments using BoKS keytab management, affected versions of boks_keytabmd generate Active Directory service-account passwords from a predictable pseudo-random sequence seeded with the current Unix timestamp. An attacker who knows the service principal and can estimate the password-change time can reproduce a limited candidate set and verify candidates offline.
Published: 2026-10-01
Score: 9.9 Critical
EPSS: n/a
KEV: No
Impact: Predictable service-account passwords leading to credential compromise
Action: Immediate Patch
AI Analysis

Impact

In affected BoKS deployments the keytab manager generates Active Directory service-account passwords from a predictable pseudo-random sequence seeded with the current Unix timestamp. Because the sequence is deterministic, an attacker who knows the service principal and can estimate the password-change time can reconstruct a limited set of candidate passwords and verify them offline, allowing credential compromise of service accounts and undermining Kerberos authentication.

Affected Systems

This flaw affects BoKS Manager installations provided by Fortra (boks-server) that use the BoKS keytab management module. Versions prior to boks-server 9.0.0.7 are vulnerable; the identified solution upgrades to that version. No other products or versions are listed.

Risk and Exploitability

The CVSS score of 9.9 indicates critical severity. EPSS is not available, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires only knowledge of the service principal and an estimation of the password-change timestamp, after which the attacker can compute the candidate passwords offline. The impact is the potential compromise of service-account credentials and denial of Kerberos authentication for affected principals.

Generated by OpenCVE AI on October 1, 2026 at 16:01 UTC.

Remediation

Vendor Solution

Upgrade the active BoKS Master to boks-server 9.0.0.7 and restart BoKS before generating replacement passwords.


Vendor Workaround

Installing the update does not secure passwords generated by an affected release. Rotate all affected or uncertain service-account passwords through BoKS keytab management and confirm distribution of the new key version. After the Active Directory domain's configured maximum service-ticket lifetime plus clock-skew allowance has elapsed, rebuild affected keytabs during a maintenance window so they retain only the current key version. Redistribute and verify the keytabs, restart or reload dependent services as required, and test Kerberos authentication. If compromise is suspected, rotate and rebuild immediately rather than waiting for existing tickets to expire.


OpenCVE Recommended Actions

  • Upgrade the active BoKS Master to boks-server 9.0.0.7 and restart BoKS before generating replacement passwords.
  • Rotate all affected or uncertain service-account passwords through BoKS keytab management and confirm distribution of the new key version.
  • After the Active Directory domain’s maximum service-ticket lifetime plus clock‑skew allowance has elapsed, rebuild affected keytabs so they retain only the current key version, redistribute and verify them, then restart or reload dependent services and test Kerberos authentication.
  • If compromise is suspected, rotate and rebuild immediately rather than waiting for existing tickets to expire.

Generated by OpenCVE AI on October 1, 2026 at 16:01 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 01 Oct 2026 14:00:00 +0000

Type Values Removed Values Added
Description In deployments using BoKS keytab management, affected versions of boks_keytabmd generate Active Directory service-account passwords from a predictable pseudo-random sequence seeded with the current Unix timestamp. An attacker who knows the service principal and can estimate the password-change time can reproduce a limited candidate set and verify candidates offline.
Title Predictable Active Directory service-account passwords in BoKS Manager
Weaknesses CWE-338
References
Metrics cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Fortra

Published:

Updated: 2026-10-01T14:43:07.294Z

Reserved: 2026-08-25T14:50:15.178Z

Link: CVE-2026-79901

cve-icon Vulnrichment

Updated: 2026-10-01T14:42:56.920Z

cve-icon NVD

Status : Deferred

Published: 2026-10-01T14:17:30.883

Modified: 2026-10-01T15:17:32.163

Link: CVE-2026-79901

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T16:15:10Z

Weaknesses
  • CWE-338

    Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)