CVE-2026-79901: Predictable Active Directory service-account passwords in BoKS Manager
In deployments using BoKS keytab management, affected versions of bokskeytabmd generate Active Directory service-account passwords from a predictable pseudo-random sequence seeded with the current Unix timestamp. An attacker who knows the service principal and can estimate the password-change time can reproduce a limited candidate set and verify candidates offline.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
boks-serverto a version that resolves this vulnerability.Fixed in 9.0.0.7 - Operational
Restart BoKS before generating replacement passwords.
Event History
Frequently Asked Questions
Which deployments are exposed?
Deployments using BoKS keytab management are exposed if they run an affected version of boks_keytabmd. The issue concerns Active Directory service-account passwords generated by that component.
What does an attacker need to exploit this?
The attacker needs to know the service principal and estimate when the password was changed. They can then reproduce a limited set of password candidates from the Unix-timestamp-seeded pseudo-random sequence and verify them offline.
Is interaction with a user required?
No. The supplied vector indicates no user interaction is required, although exploitation requires low-level privileges.