Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Upgrade to a fixed boks-client release newer than 8.1.0.29 or 9.0.0.5, then rotate machine-account passwords generated by affected versions.
Vendor Workaround
Until fixed builds are deployed, avoid running adjoin join or autoupdate operations from affected versions. If automatic machine-account password renewal is enabled, disable it temporarily or ensure renewed passwords are rotated again after upgrading to a fixed version.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 01 Oct 2026 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Fortra
Fortra core Privileged Access Manager (boks) |
|
| Vendors & Products |
Fortra
Fortra core Privileged Access Manager (boks) |
Thu, 01 Oct 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 01 Oct 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Fortra BoKS Server Agent contains a predictable password generation vulnerability in the adjoin utility. Machine-account passwords generated during Active Directory join or password renewal operations may have significantly less entropy than intended, making them more susceptible to prediction by an attacker who can estimate when the password was generated. | |
| Title | Fortra BoKS Server Agent adjoin machine-account password generation vulnerability | |
| Weaknesses | CWE-338 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Fortra
Published:
Updated: 2026-10-01T16:16:15.483Z
Reserved: 2026-05-28T16:37:54.270Z
Link: CVE-2026-9864
Updated: 2026-10-01T16:16:10.345Z
Status : Received
Published: 2026-10-01T16:18:09.417
Modified: 2026-10-01T17:17:36.303
Link: CVE-2026-9864
No data.
OpenCVE Enrichment
Updated: 2026-10-01T18:30:11Z
-
CWE-338
Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)