Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Upgrade the active BoKS Master to boks-server 9.0.0.7 and restart BoKS before generating replacement passwords.
Vendor Workaround
Installing the update does not secure passwords generated by an affected release. Rotate all affected or uncertain service-account passwords through BoKS keytab management and confirm distribution of the new key version. After the Active Directory domain's configured maximum service-ticket lifetime plus clock-skew allowance has elapsed, rebuild affected keytabs during a maintenance window so they retain only the current key version. Redistribute and verify the keytabs, restart or reload dependent services as required, and test Kerberos authentication. If compromise is suspected, rotate and rebuild immediately rather than waiting for existing tickets to expire.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 01 Oct 2026 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In deployments using BoKS keytab management, affected versions of boks_keytabmd generate Active Directory service-account passwords from a predictable pseudo-random sequence seeded with the current Unix timestamp. An attacker who knows the service principal and can estimate the password-change time can reproduce a limited candidate set and verify candidates offline. | |
| Title | Predictable Active Directory service-account passwords in BoKS Manager | |
| Weaknesses | CWE-338 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: Fortra
Published:
Updated: 2026-10-01T14:43:07.294Z
Reserved: 2026-08-25T14:50:15.178Z
Link: CVE-2026-79901
No data.
Status : Received
Published: 2026-10-01T14:17:30.883
Modified: 2026-10-01T14:17:30.883
Link: CVE-2026-79901
No data.
OpenCVE Enrichment
No data.