CVE-2026-79901

LOWCVSS 9.9 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

In deployments using BoKS keytab management, affected versions of boks_keytabmd generate Active Directory service-account passwords from a predictable pseudo-random sequence seeded with the current Unix timestamp. An attacker who knows the service principal and can estimate the password-change time can reproduce a limited candidate set and verify candidates offline.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-338

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-10-01: 110-01
Referenced assets1 URL
Full discourse1 post
  • Severity Daily@severitydaily

    Fortra's BoKS generated Active Directory service-account passwords from the clock. Installing the fix secures none of the passwords it already made, and the advisory never says so. No exploitation reported. https://severitydaily.com/fortra-boks-cve-2026-79901-keytab-prng-upgrade-does-not-secure-existing-passwords/

    0000027
    29 followersView on X

Explore more