CVE-2026-9864
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
Summary
Fortra BoKS Server Agent contains a predictable password generation vulnerability in the adjoin utility. Machine-account passwords generated during Active Directory join or password renewal operations may have significantly less entropy than intended, making them more susceptible to prediction by an attacker who can estimate when the password was generated.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Fortra | Core Privileged Access Manager (BoKS) | 8.1.0.0 <= 8.1.0.29 | affected |
| Fortra | Core Privileged Access Manager (BoKS) | 9.0.0.0 <= 9.0.0.5 | affected |
Weaknesses
- CWE-338: CWE-338 Use of cryptographically weak Pseudo-Random number generator (PRNG)
Workarounds
Until fixed builds are deployed, avoid running adjoin join or autoupdate operations from affected versions. If automatic machine-account password renewal is enabled, disable it temporarily or ensure renewed passwords are rotated again after upgrading to a fixed version.
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: none
- Automatable: no
- Technical Impact: partial
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.