Fortra patches three critical flaws in its BoKS access manager

Fortra fixed a 9.9-severity authentication bypass and two other critical bugs in BoKS, the access manager used to control Unix and Linux fleets.

MedRisk Staff
By
2 Min Read

Fortra has shipped fixes for three critical bugs in BoKS Manager, the software hospitals and labs use to centralize access control and policy across their Unix and Linux servers. The gravest of the three, CVE-2026-79901 carrying a CVSS score of 9.9, is an authentication bypass that strikes deployments which manage Active Directory service accounts through the BoKS keytab.

At the root is a weak random generator: the service account passwords come from a predictable sequence seeded by the current Unix timestamp. Fortra warns that anyone who knows the service principal and can estimate when the password rotated can rebuild a short candidate list and check it offline, using either a valid AD account or a previously captured service ticket for the needed material.

A second bug carries the id CVE-2026-79898. Rated 9.1, it is a command injection flaw that lets an already-authenticated user feed in shell commands the BoKS Master runs with root privileges. A third is logged as CVE-2026-12627 and scored 9.8, a stack buffer overflow inside autoregistration that a remote attacker could reach to corrupt memory. The vendor also cleaned up five lower-rated bugs, among them heap overflows, an out-of-bounds read and an insecure temporary file.

Health systems running BoKS should treat the patches as urgent rather than routine. Privileged-access tools sit at the heart of hospital and laboratory infrastructure, where Unix and Linux hosts run imaging, laboratory and records systems. Fortra said it has seen no sign of exploitation in the wild.

Share This Article