Skip to content
Threat Feed
high threat exploited

Critical Vulnerabilities Patched in Fortra Core Privileged Access Manager (BoKS)

Fortra released patches for three critical vulnerabilities in its Core Privileged Access Manager (BoKS) software, addressing authentication bypass, command injection, and memory corruption flaws.

CVE search metadata

CVE search record: CVE-2026-79901. Severity: critical. CVSS: 9.9. EPSS: 0.27%. KEV: no. Product: Core Privileged Access Manager (BoKS). Brief: Critical Vulnerabilities Patched in Fortra Core Privileged Access Manager (BoKS). Brief link: https://feed.craftedsignal.io/briefs/2026-10-fortra-boks-vulnerabilities/

CVE search record: CVE-2026-79898. Severity: critical. CVSS: 9.1. EPSS: 0.98%. KEV: no. Product: Core Privileged Access Manager (BoKS). Brief: Critical Vulnerabilities Patched in Fortra Core Privileged Access Manager (BoKS). Brief link: https://feed.craftedsignal.io/briefs/2026-10-fortra-boks-vulnerabilities/

CVE search record: CVE-2026-12627. Severity: critical. CVSS: 9.8. EPSS: 0.44%. KEV: no. Product: Core Privileged Access Manager (BoKS). Brief: Critical Vulnerabilities Patched in Fortra Core Privileged Access Manager (BoKS). Brief link: https://feed.craftedsignal.io/briefs/2026-10-fortra-boks-vulnerabilities/

Fortra has disclosed and patched eight vulnerabilities affecting its Core Privileged Access Manager (BoKS), a centralized management solution for Unix and Linux environments. Among the eight, three are critical in severity and require immediate attention. CVE-2026-79901 (CVSS 9.9) allows for authentication bypass because Active Directory service account passwords are generated using a predictable pseudo-random sequence seeded with the current Unix timestamp. CVE-2026-79898 (CVSS 9.1) is a command injection flaw in the 'crlserver' component that can be exploited via BCC or the WSI REST/SOAP API to execute arbitrary commands as root. Finally, CVE-2026-12627 (CVSS 9.8) is a stack buffer overflow in the autoregistration functionality that could lead to memory corruption. While Fortra has not observed exploitation in the wild, the administrative nature of the impacted software makes these high-value targets for adversaries seeking to compromise privileged access infrastructure.

Impact

Successful exploitation of these vulnerabilities could result in full administrative compromise of the BoKS environment, enabling unauthorized access to managed Unix/Linux fleets, privilege escalation to root, and potential persistence via memory corruption. The software is used for sensitive policy enforcement and access control, meaning impacted organizations risk the integrity and confidentiality of their privileged identity management infrastructure.

Recommendation

  • Patch all deployments of Fortra Core Privileged Access Manager (BoKS) immediately by applying the vendor-supplied updates.
  • Audit access to the WSI REST and SOAP APIs to ensure only authorized endpoints can interact with the 'crlserver' component.
  • Review Active Directory service account management policies for BoKS to identify potential reliance on the vulnerable 'keytab' generation process.
  • Monitor logs for unauthorized access attempts targeting BoKS administrative interfaces or API endpoints.

Immediate actions

Upgrade Core Privileged Access Manager (BoKS) to the latest version as per Fortra product security guidelines

IT Operations 24h

Mitigations

Restrict network access to the WSI REST and SOAP APIs to trusted management segments only

immediate IT Operations

CVE-2026-79898