Predictable Active Directory service-account passwords in BoKS Manager

FI-2026-012 - Predictable Active Directory service-account passwords in BoKS Manager

Severity
Critical
Published Date
01-Oct-2026
Updated Date
01-Oct-2026
Vulnerabilities
CVE-2026-79901
 
Notes
Description

In deployments using BoKS keytab management, affected versions of boks_keytabmd generate Active Directory service-account passwords from a predictable pseudo-random sequence seeded with the current Unix timestamp. An attacker who knows the service principal and can estimate the password-change time can reproduce a limited candidate set and verify candidates offline.

 

Vulnerabilities

 
Predictable Active Directory service-account passwords in BoKS Manager
Severity
Critical
CVE
CVE-2026-79901
CWE
CWE-338 :Use of cryptographically weak Pseudo-Random number generator (PRNG)
Discovery Date
25-Aug-2026
CSSv3.1
9.9 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H)
Affected Products
Vulnerability Notes
Remediation: Mitigation

Only BoKS Manager deployments using BoKS keytab management to manage Active Directory service accounts are affected. Deployments that do not use BoKS keytab management are not affected. Administrator-supplied initial service-account passwords are not generated through the vulnerable code path and are not affected.

 

Exploitation requires knowledge of the affected service principal, an estimate of the password-change time, and suitable Kerberos ticket material. A standard authenticated Active Directory account can ordinarily request a service ticket for an SPN assigned to the affected account; administrative access to BoKS, the service host, or its keytab is not normally required. A previously captured service ticket can alternatively provide offline verification material.

 
References