Skip to content

Fortra patches critical BoKS flaws: unauth RCE and AD bypass

Fortra fixed eight BoKS Core PAM flaws, three critical: an unauth stack overflow (CVE-2026-12627, 9.8), a crlserver command injection to root, and predictable AD passwords. Fixed in 8.1.0.24/9.0.0.7.

Published 3 min read

Fortra has patched eight vulnerabilities in Core Privileged Access Manager (BoKS), three of them critical: an unauthenticated stack buffer overflow (CVE-2026-12627, CVSS 9.8), a command injection that runs as root (CVE-2026-79898, 9.1), and a predictable password generator for Active Directory service accounts (CVE-2026-79901, 9.9). The fixes ship in 8.1.0.24 and 9.0.0.7. BoKS is a Unix/Linux PAM product; the Master server it protects is exactly the box you don't want reachable pre-auth.

What the bugs do

Details are in Fortra's product security advisories, including the autoregistration advisory FI-2026-007.

  • CVE-2026-12627 (9.8) — a stack-based buffer overflow (CWE-121) in boks_autoregisterd. A remote, unauthenticated attacker can trigger memory corruption via crafted client responses, with potential arbitrary code execution on the BoKS infrastructure. This is the one that matters most: no credentials, no interaction, network-reachable.
  • CVE-2026-79898 (9.1) — command injection in crlserver. An authenticated user allowed to add CRL URLs through BCC, the WSI REST/SOAP API, or the cacrl CLI can get shell command substitution processed as root on the BoKS Master.
  • CVE-2026-79901 (9.9) — AD service-account passwords are generated from a predictable pseudo-random sequence seeded with the current Unix timestamp. An attacker who knows the service principal and can approximate when the password was rotated can compute candidate passwords and verify them offline, without touching the BoKS system. This one only affects installations that use BoKS keytab file management to administer AD service accounts.

Five more high/medium-severity issues round out the release: heap overflows, an out-of-bounds read, and an insecure temporary file, per SecurityWeek.

Affected versions

  • Vulnerable: branch 8.1 from 8.1.0.0 through 8.1.0.23; branch 9.0 from 9.0.0.0 through 9.0.0.6.
  • Fixed: 8.1.0.24 and 9.0.0.7 (or later).

Spain's INCIBE-CERT relayed the same version ranges.

Exploitation status

No in-the-wild exploitation is reported. Fortra's advisories do not cite any, and neither does SecurityWeek. There is no public PoC at the time of writing. The risk profile still argues for urgency: an unauthenticated memory-corruption bug in a privileged-access gateway is the kind of target that attracts PoC work quickly.

Action checklist

  1. Upgrade the BoKS Master and replicas to 8.1.0.24 or 9.0.0.7. Patch the Master first — it is the blast radius for CVE-2026-79898 and CVE-2026-12627.
  2. Restrict network reach to boks_autoregisterd until patched. The pre-auth overflow needs to talk to that service; firewall it to known hosts.
  3. Rotate AD service-account passwords managed via BoKS keytab after patching if you ran an affected version — CVE-2026-79901 means prior passwords may be derivable offline. Patching stops future prediction; it does not invalidate passwords an attacker could already have computed.
  4. Audit CRL-URL permissions (BCC, WSI REST/SOAP, cacrl) and pull them back to the minimum set of operators, limiting CVE-2026-79898 exposure.

Context

Fortra is the vendor behind GoAnywhere MFT, whose 2023 zero-day (CVE-2023-0669) was mass-exploited by Cl0p — a reminder that attackers prize Fortra's access- and transfer-tier products because of what sits behind them. A PAM Master holds the keys to a Unix estate; the predictable-password bug is the standout here, because a timestamp-seeded PRNG for credentials is a design flaw, not a coding slip, and offline-derivable passwords survive the patch. Treat the rotation step as mandatory, not optional.

Related stories