CVE-2026-79901
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Summary
In deployments using BoKS keytab management, affected versions of boks_keytabmd generate Active Directory service-account passwords from a predictable pseudo-random sequence seeded with the current Unix timestamp. An attacker who knows the service principal and can estimate the password-change time can reproduce a limited candidate set and verify candidates offline.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Fortra | BoKS Manager boks-server | 0 < 9.0.0.6 | affected |
Weaknesses
- CWE-338: CWE-338 Use of cryptographically weak Pseudo-Random number generator (PRNG)
Workarounds
Installing the update does not secure passwords generated by an affected release. Rotate all affected or uncertain service-account passwords through BoKS keytab management and confirm distribution of the new key version. After the Active Directory domain's configured maximum service-ticket lifetime plus clock-skew allowance has elapsed, rebuild affected keytabs during a maintenance window so they retain only the current key version. Redistribute and verify the keytabs, restart or reload dependent services as required, and test Kerberos authentication. If compromise is suspected, rotate and rebuild immediately rather than waiting for existing tickets to expire.
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: none
- Automatable: no
- Technical Impact: total
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.