CVE-2026-9864: Fortra BoKS Server Agent adjoin machine-account password generation vulnerability
Fortra BoKS Server Agent contains a predictable password generation vulnerability in the adjoin utility. Machine-account passwords generated during Active Directory join or password renewal operations may have significantly less entropy than intended, making them more susceptible to prediction by an attacker who can estimate when the password was generated.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Operational
Rotate machine-account passwords generated by boks-client versions affected by the adjoin vulnerability.
Event History
Frequently Asked Questions
What must an attacker know or be able to do to exploit this issue?
An attacker needs to be able to estimate when a machine-account password was generated, such as during an Active Directory join or password renewal operation. The issue is that the generated password may have substantially less entropy than intended, making prediction more feasible.
Which operations can create an exposed machine-account password?
The affected password generation occurs in the adjoin utility during Active Directory join operations and machine-account password renewal operations.
Is authentication required to exploit the vulnerability?
No authentication is required according to the provided vector. However, exploitation has high attack complexity because the attacker must be able to estimate the password-generation time.