Fortra BoKS Critical Vulnerability Cluster Hunt

Threat Overview

Fortra published eight Core Privileged Access Manager (BoKS) advisories on October 1, 2026, including three critical vulnerabilities spanning identity, privileged command execution, and unauthenticated memory corruption. CVE-2026-79901 (CVSS 9.9) affects deployments using BoKS keytab management for Active Directory service accounts: boks_keytabmd generates passwords from a predictable sequence seeded with the Unix timestamp, allowing an attacker who knows the service principal and approximates the change time to derive a small candidate set and verify it offline with Kerberos ticket material. A standard authenticated AD user can normally request the required service ticket.

CVE-2026-79898 (CVSS 9.1) is command injection in crlserver. An authenticated BoKS user authorized to add CRL URLs through BCC, WSI REST/SOAP, or cacrl can cause shell command substitution to execute as root on the BoKS Master. CVE-2026-12627 (CVSS 9.8) is a stack buffer overflow in boks_autoregisterd; a remote attacker with network access to the autoregistration service may trigger memory corruption during client response processing.

Fortra and subsequent reporting did not identify in-the-wild exploitation as of October 5. No public exploit syntax or IOCs were supplied. The hunt therefore emphasizes affected BoKS inventory, crlserver child processes, suspicious CRL administration, autoregistration crashes, access to the default autoregistration port, AD/Kerberos activity involving BoKS-managed service accounts, and root-level persistence on BoKS Masters.

References

Impacted Systems

  • Vendor/product: Fortra Core Privileged Access Manager (BoKS), including BoKS Manager/Master services.
  • Affected builds: BoKS Manager boks-server before 8.1.0.24 and before 9.0.0.7 for the October advisory set. The CVE record for CVE-2026-79901 identifies boks-server versions before 9.0.0.6; use 9.0.0.7 as the operational remediation target for the full cluster.
  • Fixed builds: boks-server 8.1.0.24 or 9.0.0.7, as applicable to the supported branch.
  • Platform/deployment: Self-managed Unix/Linux privileged-access infrastructure; BoKS Master is the central trust and policy-management role.
  • CVE-2026-79901 prerequisite: BoKS keytab management is used for AD service accounts; attacker knows the SPN, approximates password-change time, and has Kerberos service-ticket material. Deployments not using BoKS keytab management and administrator-supplied initial passwords are not affected by this code path.
  • CVE-2026-79898 prerequisite: Authenticated user with permission to add CRL URLs via network-accessible BCC/WSI or local cacrl; injected substitution runs as root on the Master.
  • CVE-2026-12627 prerequisite/exposure: Network access to boks_autoregisterd, which listens on TCP 6507 by default; authentication is not required according to the CVSS vector.

Why this matters

BoKS centralizes privileged access across Unix/Linux fleets and may manage AD service-account secrets. Compromise of the Master can cross operating-system and identity boundaries. The cluster offers three materially different paths—offline recovery of managed credentials, authorized-user-to-root command injection, and unauthenticated memory corruption—so a single IOC query would provide inadequate coverage.

Exploitation Status

No confirmed in-the-wild exploitation was identified in the cited sources as of October 5, 2026. The vulnerabilities and exploit preconditions are vendor-confirmed. No public payload, attacker infrastructure, malware hash, or validated intrusion chain was published. Behavioral results should be treated as leads requiring BoKS and identity context, not proof that a specific CVE was exploited.

What this hunt looks for

BoKS services and versions, crlserver child processes, command-substitution characters in CRL administration, boks_autoregisterd crashes, concentrated or rare TCP/6507 sources, Kerberos activity for confirmed BoKS-managed SPNs, service-account password changes, and root persistence.

Required logs

BoKS and Unix/Linux Syslog or audit data; Microsoft Defender for Endpoint DeviceProcessEvents and DeviceFileEvents on the BoKS Master; firewall or flow telemetry in CommonSecurityLog for TCP/6507 and management paths; and domain-controller SecurityEvent data for Kerberos and service-account changes.

Hunt 1 — First-pass BoKS process and package inventory

let lookback = 14d;
union isfuzzy=true
(
    DeviceProcessEvents
    | where Timestamp >= ago(lookback)
    | where FileName startswith "boks_" or FileName in~ ("crlserver", "cacrl", "bcc") or FolderPath has_any ("/boks/", "/BoKS/")
    | project TimeGenerated=Timestamp, Computer=DeviceName, Source="MDE", Detail=strcat(FolderPath, "/", FileName, " ", ProcessCommandLine)
),
(
    Syslog
    | where TimeGenerated >= ago(lookback)
    | where ProcessName startswith "boks" or ProcessName in~ ("crlserver", "cacrl") or SyslogMessage has_any ("boks-server", "boks_autoregisterd", "boks_keytabmd")
    | project TimeGenerated, Computer, Source="Syslog", Detail=strcat(ProcessName, ": ", SyslogMessage)
)
| summarize FirstSeen=min(TimeGenerated), LastSeen=max(TimeGenerated), Evidence=make_set(Detail, 20), Sources=make_set(Source, 5) by Computer
| order by LastSeen desc

Hunt 2 — crlserver spawning a shell or network utility

let lookback = 30d;
DeviceProcessEvents
| where Timestamp >= ago(lookback)
| where InitiatingProcessFileName =~ "crlserver" or InitiatingProcessCommandLine has "crlserver"
| where FileName in~ ("sh", "bash", "dash", "ksh", "zsh", "curl", "wget", "nc", "ncat", "socat", "python", "python3", "perl")
| project Timestamp, DeviceName, AccountName, FileName, ProcessCommandLine, SHA256, InitiatingProcessFileName, InitiatingProcessCommandLine
| order by Timestamp desc

Hunt 3 — Suspicious CRL URL administration in BoKS logs

let lookback = 30d;
Syslog
| where TimeGenerated >= ago(lookback)
| where ProcessName has_any ("crlserver", "cacrl", "bcc", "wsi") or SyslogMessage has_any ("CRL URL", "cacrl", "crlserver")
| where SyslogMessage has_any ("$(", "`", ";", "|", "&&", "${", "/bin/sh", "/bin/bash", "curl ", "wget ")
| project TimeGenerated, Computer, Facility, SeverityLevel, ProcessName, SyslogMessage
| order by TimeGenerated desc

Hunt 4 — boks_autoregisterd crash or memory-fault signals

let lookback = 30d;
Syslog
| where TimeGenerated >= ago(lookback)
| where ProcessName has "boks_autoregisterd" or SyslogMessage has "boks_autoregisterd"
| where SyslogMessage has_any ("segfault", "segmentation fault", "stack smashing", "buffer overflow", "core dumped", "aborted", "SIGSEGV", "restarted", "respawn")
| project TimeGenerated, Computer, Facility, SeverityLevel, ProcessName, SyslogMessage
| order by TimeGenerated desc

Hunt 5 — Connection concentration to the default autoregistration service

let lookback = 30d;
CommonSecurityLog
| where TimeGenerated >= ago(lookback)
| where DestinationPort == 6507
| summarize Connections=count(), FirstSeen=min(TimeGenerated), LastSeen=max(TimeGenerated), Actions=make_set(DeviceAction, 10), SourcePorts=dcount(SourcePort) by SourceIP, DestinationIP, bin(TimeGenerated, 10m)
| where Connections >= 10
| order by Connections desc

Hunt 6 — Rare sources connecting to BoKS TCP 6507

let baseline = 30d;
let recent = 2d;
let Known = CommonSecurityLog
| where TimeGenerated between (ago(baseline) .. ago(recent)) and DestinationPort == 6507
| summarize by SourceIP, DestinationIP;
CommonSecurityLog
| where TimeGenerated >= ago(recent) and DestinationPort == 6507
| join kind=leftanti Known on SourceIP, DestinationIP
| summarize Connections=count(), FirstSeen=min(TimeGenerated), LastSeen=max(TimeGenerated), Actions=make_set(DeviceAction, 10) by SourceIP, DestinationIP
| order by Connections desc

Hunt 7 — Kerberos service-ticket bursts for known BoKS-managed SPNs

let lookback = 30d;
let BoKSManagedSPNs = dynamic(["REPLACE_WITH_CONFIRMED_BOKS_MANAGED_SPN"]);
SecurityEvent
| where TimeGenerated >= ago(lookback) and EventID == 4769
| where ServiceName in~ (BoKSManagedSPNs)
| summarize Tickets=count(), SourceHosts=dcount(WorkstationName), SourceIPs=dcount(IpAddress), EncryptionTypes=make_set(TicketEncryptionType, 10), Failures=countif(Status != "0x0") by Account, ServiceName, bin(TimeGenerated, 30m)
| where Tickets >= 20 or Failures > 0
| order by Tickets desc

Hunt 8 — Password changes affecting confirmed BoKS-managed AD service accounts

let lookback = 30d;
let BoKSManagedAccounts = dynamic(["REPLACE_WITH_CONFIRMED_BOKS_MANAGED_ACCOUNT"]);
SecurityEvent
| where TimeGenerated >= ago(lookback) and EventID in (4723, 4724, 4738)
| where TargetAccount in~ (BoKSManagedAccounts) or TargetUserName in~ (BoKSManagedAccounts)
| project TimeGenerated, Computer, EventID, SubjectAccount, SubjectUserName, TargetAccount, TargetUserName, Activity
| order by TimeGenerated desc

Hunt 9 — Root persistence changes on a BoKS Master

let lookback = 30d;
DeviceFileEvents
| where Timestamp >= ago(lookback)
| where InitiatingProcessAccountName =~ "root"
| where FolderPath has_any ("/etc/cron", "/etc/systemd/system/", "/usr/lib/systemd/system/", "/root/.ssh/", "/etc/sudoers", "/etc/ld.so.preload")
| where InitiatingProcessFileName in~ ("crlserver", "sh", "bash", "dash", "curl", "wget", "python", "python3") or InitiatingProcessParentFileName =~ "crlserver"
| project Timestamp, DeviceName, ActionType, FolderPath, FileName, SHA256, InitiatingProcessAccountName, InitiatingProcessFileName, InitiatingProcessCommandLine
| order by Timestamp desc

Detection Notes

  • Hunt 1 is the required first pass. Confirm package versions with the authoritative package manager or Fortra tooling; process telemetry rarely contains reliable BoKS build numbers.
  • Hunt 2 is high signal because crlserver should not ordinarily spawn an interactive shell or download utility. Endpoint coverage on the Linux Master is required.
  • Hunt 3 detects generic command-substitution characters in CRL administration logs. URLs can legitimately contain some punctuation, and BCC/WSI may not log the full submitted value; validate against approved CRL endpoints.
  • Hunts 4–6 address CVE-2026-12627. A crash is not proof of exploitation, and successful memory corruption may not emit a distinctive message. Restrict the target set to known BoKS Master IPs.
  • Hunts 7 and 8 require replacing the explicit placeholders with confirmed BoKS-managed SPNs and accounts. Broad, unscoped Kerberos analytics would be noisy and would not specifically test CVE-2026-79901.
  • Offline password candidate testing is not visible in Sentinel. Domain-controller events can show ticket requests and subsequent use, but cannot prove how a password was recovered.
  • Missing Linux endpoint telemetry, BoKS/Syslog, firewall flow data, or domain-controller Security Events prevents the relevant exploitation path from being visible in Sentinel.