CVE-2026-9864

Summary

Fortra BoKS Server Agent contains a predictable password generation vulnerability in the adjoin utility. Machine-account passwords generated during Active Directory join or password renewal operations may have significantly less entropy than intended, making them more susceptible to prediction by an attacker who can estimate when the password was generated.

Affected Software

VendorProductVersion RangeStatus
FortraCore Privileged Access Manager (BoKS)8.1.0.0 <= 8.1.0.29affected
FortraCore Privileged Access Manager (BoKS)9.0.0.0 <= 9.0.0.5affected

Weaknesses

  • CWE-338: CWE-338 Use of cryptographically weak Pseudo-Random number generator (PRNG)

Workarounds

Until fixed builds are deployed, avoid running adjoin join or autoupdate operations from affected versions. If automatic machine-account password renewal is enabled, disable it temporarily or ensure renewed passwords are rotated again after upgrading to a fixed version.

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References