News Date: 2026-10-03
Fortra has released security updates for eight vulnerabilities in Core Privileged Access Manager, commonly known as BoKS. Three of the flaws are rated critical and could allow attackers to bypass authentication controls, execute commands as root or trigger memory corruption in environments that centrally manage Unix and Linux access.
A privileged platform becomes the target
BoKS is designed to enforce account policies and access controls across large server fleets. That central role makes it operationally useful, but it also means a compromised deployment could become a bridge into numerous systems that administrators believed were protected by consistent privileged-access rules.
The most severe issue, CVE-2026-79901, carries a CVSS score of 9.9. According to Fortra, affected configurations generate certain Active Directory service-account passwords from a predictable pseudo-random sequence seeded with the current Unix timestamp. An attacker who knows the service principal and can estimate when the password changed may be able to create a manageable list of candidates and test them offline using Kerberos material.
A second vulnerability, CVE-2026-79898, could let an authenticated user inject shell commands that are processed as root on the BoKS Master. The third critical flaw, CVE-2026-12627, is a stack buffer overflow in the autoregistration functionality that could allow a remote attacker to cause memory corruption. Five additional vulnerabilities address buffer handling, out-of-bounds reads, insecure temporary files and predictable password generation.
Recommended defensive actions
- Upgrade every affected BoKS component rather than patching only the central manager.
- Rotate relevant Active Directory service-account passwords and regenerate keytab material.
- Review Kerberos ticket activity for unusual requests involving BoKS-managed service principals.
- Restrict access to management, REST and SOAP interfaces to dedicated administrative networks.
- Inspect BoKS Master systems for unexpected root processes, configuration changes and persistence.
Expert view
Fortra has not reported exploitation in the wild, but I believe organizations should avoid treating that as a reason to delay. Privileged access systems sit close to an enterprise's most sensitive credentials and administrative pathways. A vulnerability in ordinary software may expose one server, while a vulnerability in a privileged management platform can undermine the trust model protecting an entire fleet. Patching should therefore be followed by credential rotation and investigation, not treated as a complete response by itself.
