Fortra Patches Critical BoKS PAM Vulnerabilities

Fortra Patches Critical Flaws in BoKS Privileged Access Manager

CRITICAL
October 4, 2026
4m read
VulnerabilityPatch Management

Related Entities

Organizations

Products & Tech

Core Privileged Access Manager (BoKS)Active Directory

CVE Identifiers

CVE-2026-79901
CRITICAL
CVSS:9.9
CVE-2026-79898
CRITICAL
CVSS:9.1
CVE-2026-12627
CRITICAL
CVSS:9.8

Full Report

Executive Summary

Fortra has issued patches for eight vulnerabilities in its Core Privileged Access Manager (BoKS) solution, a platform for managing access control on Unix and Linux systems. Three of these vulnerabilities are rated critical and expose customers to significant risk, including authentication bypass, remote command execution with root privileges, and system compromise. The most severe flaw, CVE-2026-79901, is an authentication bypass with a CVSS score of 9.9. The other critical issues are CVE-2026-79898 (CVSS 9.1) and CVE-2026-12627 (CVSS 9.8). Fortra has stated it has no evidence of these flaws being exploited in the wild, but due to their severity, immediate patching is strongly recommended.


Vulnerability Details

The three critical vulnerabilities present distinct paths to system compromise:

  • CVE-2026-79901 (CVSS 9.9) - Authentication Bypass: This flaw exists in BoKS Manager deployments using BoKS keytab for managing Active Directory service account passwords. The password generation process uses a predictable pseudo-random number generator seeded with the current Unix timestamp. An attacker who knows the service principal name and can estimate the time of a password change can generate a list of possible passwords and validate them offline, eventually gaining unauthorized access without triggering failed login alerts.

  • CVE-2026-79898 (CVSS 9.1) - Command Injection: A command injection vulnerability in the crlserver component allows an authenticated user to execute arbitrary shell commands with root privileges on the BoKS Master server. This can be exploited remotely via the BCC and WSI REST or SOAP APIs, bypassing the need for local sudo rules.

  • CVE-2026-12627 (CVSS 9.8) - Stack Buffer Overflow: This flaw in the autoregistration function of BoKS can be triggered by a remote, unauthenticated attacker. It leads to memory corruption, which could cause a denial of service or, potentially, allow for arbitrary code execution.

Affected Systems

  • Fortra Core Privileged Access Manager (BoKS)
  • Specific versions affected have been detailed in Fortra's security advisory.

Exploitation Status

As of October 3, 2026, Fortra is not aware of any of these vulnerabilities being actively exploited in the wild. However, due to the public disclosure and the critical nature of the flaws, the risk of future exploitation is high.

Impact Assessment

Successful exploitation of these vulnerabilities could lead to a complete compromise of the BoKS management platform and, by extension, the entire fleet of Unix and Linux systems it manages. An attacker could gain root-level access across the environment, steal sensitive data, deploy ransomware, and establish persistent control. The authentication bypass flaw is particularly dangerous as it allows for stealthy initial access.

Cyber Observables — Hunting Hints

Security teams may want to hunt for the following patterns to identify vulnerable systems or exploitation attempts:

Type
process_name
Value
crlserver
Description
Monitor for unusual child processes spawned by the crlserver process, which could indicate command injection.
Context
EDR, Sysmon (Event ID 1)
Type
url_pattern
Value
/bcc/, /wsi/
Description
Look for anomalous requests to the BCC and WSI REST/SOAP APIs.
Context
Web server logs, API Gateway Logs
Type
network_traffic_pattern
Value
Traffic to BoKS autoregistration port from untrusted sources.
Description
Could indicate attempts to trigger the buffer overflow.
Context
Firewall logs, IDS/IPS

Detection Methods

  • Log Analysis: Monitor BoKS Manager logs for any unusual authentication patterns or errors, especially related to keytab management. Review API logs for the crlserver for any suspicious commands or parameters.
  • File Integrity Monitoring: Monitor critical BoKS binaries and configuration files for any unauthorized changes.
  • Vulnerability Scanning: Use vulnerability scanners with updated plugins to identify unpatched BoKS instances within the environment.

Remediation Steps

  1. Apply Patches: The primary and most effective remediation is to apply the security patches provided by Fortra immediately. This is a critical action, as per M1051 - Update Software.
  2. Restrict Network Access: As a compensating control, restrict network access to the BoKS Manager and its API endpoints. Access should be limited to trusted administrative workstations and servers only, following the principle of M1035 - Limit Access to Resource Over Network.
  3. Review Accounts: Audit all accounts within BoKS, especially service accounts, to ensure they adhere to the principle of least privilege.

Timeline of Events

1
October 4, 2026
This article was published

MITRE ATT&CK Mitigations

The most critical action is to apply the security patches provided by Fortra to eliminate the vulnerabilities.

Restricting network access to the BoKS management interfaces to only authorized personnel and systems can serve as a powerful compensating control.

Since BoKS is a PAM tool itself, ensuring its own security is paramount. Auditing its configuration and the accounts it manages is a crucial part of the security lifecycle.

D3FEND Defensive Countermeasures

The immediate and primary response to these critical vulnerabilities is to apply the security patches released by Fortra. Given the severity of the flaws (CVSS up to 9.9), this should be treated as an emergency change. Organizations should prioritize patching internet-facing BoKS instances first, followed by internal management servers. Delaying these patches leaves a direct path for attackers to gain root-level control over the entire managed Unix/Linux estate. A robust patch management process is the definitive countermeasure for eliminating these specific risks.

As a vital compensating control, organizations must enforce strict network filtering for all BoKS management interfaces (including web UIs and APIs). These interfaces should never be exposed directly to the internet. Access must be restricted using firewall rules to a small, well-defined set of trusted IP addresses, such as corporate VPN ranges or dedicated administrative jump boxes. This directly mitigates the risk from the unauthenticated buffer overflow (CVE-2026-12627) and makes it significantly harder for an attacker to reach the vulnerable endpoints for the other flaws.

To detect potential exploitation of the command injection flaw (CVE-2026-79898), security teams should use an Endpoint Detection and Response (EDR) tool or Sysmon to monitor process relationships on the BoKS Master server. Specifically, they should create detection rules that alert on the crlserver process spawning any unexpected child processes, especially shells like sh, bash, or scripting interpreters like python or perl. A properly functioning crlserver should have a very predictable set of child processes, making any deviation a high-fidelity indicator of compromise.

Article Author

Jason Gomes

Jason Gomes

• Cybersecurity Practitioner

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.

Threat Intelligence & AnalysisSecurity Orchestration (SOAR/XSOAR)Incident Response & Digital ForensicsSecurity Operations Center (SOC)SIEM & Security AnalyticsCyber Fusion & Threat SharingSecurity Automation & IntegrationManaged Detection & Response (MDR)

Editorial Standards & Analyst Review

CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.

Tags

VulnerabilityFortraBoKSPAMCVELinuxUnixPatch Management

📢 Share This Article

Help others stay informed about cybersecurity threats

🎯 MITRE ATT&CK Mapped

Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.

🧠 Enriched & Analyzed

Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.

🛡️ Actionable Guidance

Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.

🔗 STIX Visualizer

Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.

⚡ Sigma Generator

Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.