Description
In deployments using BoKS keytab management, affected versions of boks_keytabmd generate Active Directory service-account passwords from a predictable pseudo-random sequence seeded with the current Unix timestamp. An attacker who knows the service principal and can estimate the password-change time can reproduce a limited candidate set and verify candidates offline.
Published: 2026-10-01
Score: 9.9 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

Vendor Solution

Upgrade the active BoKS Master to boks-server 9.0.0.7 and restart BoKS before generating replacement passwords.


Vendor Workaround

Installing the update does not secure passwords generated by an affected release. Rotate all affected or uncertain service-account passwords through BoKS keytab management and confirm distribution of the new key version. After the Active Directory domain's configured maximum service-ticket lifetime plus clock-skew allowance has elapsed, rebuild affected keytabs during a maintenance window so they retain only the current key version. Redistribute and verify the keytabs, restart or reload dependent services as required, and test Kerberos authentication. If compromise is suspected, rotate and rebuild immediately rather than waiting for existing tickets to expire.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 01 Oct 2026 14:00:00 +0000

Type Values Removed Values Added
Description In deployments using BoKS keytab management, affected versions of boks_keytabmd generate Active Directory service-account passwords from a predictable pseudo-random sequence seeded with the current Unix timestamp. An attacker who knows the service principal and can estimate the password-change time can reproduce a limited candidate set and verify candidates offline.
Title Predictable Active Directory service-account passwords in BoKS Manager
Weaknesses CWE-338
References
Metrics cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Fortra

Published:

Updated: 2026-10-01T14:43:07.294Z

Reserved: 2026-08-25T14:50:15.178Z

Link: CVE-2026-79901

cve-icon Vulnrichment

Updated: 2026-10-01T14:42:56.920Z

cve-icon NVD

Status : Deferred

Published: 2026-10-01T14:17:30.883

Modified: 2026-10-01T15:17:32.163

Link: CVE-2026-79901

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses
  • CWE-338

    Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)