Back

MEDIUM

Fortra BoKS Server Agent adjoin machine-account password generation vulnerability

Published Oct 1, 2026

Description

Fortra BoKS Server Agent contains a predictable password generation vulnerability in the adjoin utility. Machine-account passwords generated during Active Directory join or password renewal operations may have significantly less entropy than intended, making them more susceptible to prediction by an attacker who can estimate when the password was generated.

Affected products

Remediation

Vendor solution

Upgrade to a fixed boks-client release newer than 8.1.0.29 or 9.0.0.5, then rotate machine-account passwords generated by affected versions.

Weaknesses (1)

References (2)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner Fortra
Published Oct 1, 2026
Updated Oct 1, 2026
Reserved May 28, 2026

CISA Vulnrichment

Updated Oct 1, 2026

NVD

Status Received
Modified Oct 1, 2026

Red Hat

No data

ENISA EUVD

Assigner Fortra
Published Oct 1, 2026
Updated Oct 1, 2026

GitHub

No data