{"api_version":"1","generated_at":"2026-10-01T21:50:46+00:00","cve":"CVE-2026-9864","urls":{"html":"https://cve.report/CVE-2026-9864","api":"https://cve.report/api/cve/CVE-2026-9864.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-9864","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-9864"},"summary":{"title":"Fortra BoKS Server Agent adjoin machine-account password generation vulnerability","description":"Fortra BoKS Server Agent contains a predictable password generation vulnerability in the adjoin utility. Machine-account passwords generated during Active Directory join or password renewal operations may have significantly less entropy than intended, making them more susceptible to prediction by an attacker who can estimate when the password was generated.","state":"PUBLISHED","assigner":"Fortra","published_at":"2026-10-01 16:18:09","updated_at":"2026-10-01 20:34:26"},"problem_types":["CWE-338","CWE-338 CWE-338 Use of cryptographically weak Pseudo-Random number generator (PRNG)"],"metrics":[{"version":"3.1","source":"df4dee71-de3a-4139-9588-11b62fe6c0ff","type":"Secondary","score":"4.8","severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N","baseScore":4.8,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"}},{"version":"3.1","source":"CNA","type":"CVSS","score":"4.8","severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N","data":{"attackComplexity":"HIGH","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":4.8,"baseSeverity":"MEDIUM","confidentialityImpact":"LOW","integrityImpact":"LOW","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N","version":"3.1"}}],"references":[{"url":"https://www.fortra.com/security/advisories/product-security/fi-2026-018","name":"https://www.fortra.com/security/advisories/product-security/fi-2026-018","refsource":"df4dee71-de3a-4139-9588-11b62fe6c0ff","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-9864","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-9864","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Fortra","product":"Core Privileged Access Manager (BoKS)","version":"affected 8.1.0.0 8.1.0.29 custom","platforms":[]},{"source":"CNA","vendor":"Fortra","product":"Core Privileged Access Manager (BoKS)","version":"affected 9.0.0.0 9.0.0.5 custom","platforms":[]}],"timeline":[],"solutions":[{"source":"CNA","title":"","value":"Upgrade to a fixed boks-client release newer than 8.1.0.29 or 9.0.0.5, then rotate machine-account passwords generated by affected versions.","time":"","lang":"en"}],"workarounds":[{"source":"CNA","title":"","value":"Until fixed builds are deployed, avoid running adjoin join or autoupdate operations from affected versions. If automatic machine-account password renewal is enabled, disable it temporarily or ensure renewed passwords are rotated again after upgrading to a fixed version.","time":"","lang":"en"}],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"metrics":[{"other":{"content":{"id":"CVE-2026-9864","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","timestamp":"2026-10-01T16:16:03.897430Z","version":"2.0.3"},"type":"ssvc"}}],"providerMetadata":{"dateUpdated":"2026-10-01T16:16:15.483Z","orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP"},"title":"CISA ADP Vulnrichment"}],"cna":{"affected":[{"defaultStatus":"unknown","modules":["adjoin"],"product":"Core Privileged Access Manager (BoKS)","vendor":"Fortra","versions":[{"lessThanOrEqual":"8.1.0.29","status":"affected","version":"8.1.0.0","versionType":"custom"},{"lessThanOrEqual":"9.0.0.5","status":"affected","version":"9.0.0.0","versionType":"custom"}]}],"descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"Fortra BoKS Server Agent contains a predictable password generation vulnerability in the adjoin utility. Machine-account passwords generated during Active Directory join or password renewal operations may have significantly less entropy than intended, making them more susceptible to prediction by an attacker who can estimate when the password was generated."}],"value":"Fortra BoKS Server Agent contains a predictable password generation vulnerability in the adjoin utility. Machine-account passwords generated during Active Directory join or password renewal operations may have significantly less entropy than intended, making them more susceptible to prediction by an attacker who can estimate when the password was generated."}],"impacts":[{"capecId":"CAPEC-49","descriptions":[{"lang":"en","value":"CAPEC-49 Password Brute Forcing"}]}],"metrics":[{"cvssV3_1":{"attackComplexity":"HIGH","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":4.8,"baseSeverity":"MEDIUM","confidentialityImpact":"LOW","integrityImpact":"LOW","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N","version":"3.1"},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]}],"problemTypes":[{"descriptions":[{"cweId":"CWE-338","description":"CWE-338 Use of cryptographically weak Pseudo-Random number generator (PRNG)","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-10-01T16:00:25.899Z","orgId":"df4dee71-de3a-4139-9588-11b62fe6c0ff","shortName":"Fortra"},"references":[{"url":"https://www.fortra.com/security/advisories/product-security/fi-2026-018"}],"solutions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"Upgrade to a fixed boks-client release newer than 8.1.0.29 or 9.0.0.5, then rotate machine-account passwords generated by affected versions."}],"value":"Upgrade to a fixed boks-client release newer than 8.1.0.29 or 9.0.0.5, then rotate machine-account passwords generated by affected versions."}],"source":{"discovery":"INTERNAL"},"title":"Fortra BoKS Server Agent adjoin machine-account password generation vulnerability","workarounds":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"Until fixed builds are deployed, avoid running adjoin join or autoupdate operations from affected versions. If automatic machine-account password renewal is enabled, disable it temporarily or ensure renewed passwords are rotated again after upgrading to a fixed version."}],"value":"Until fixed builds are deployed, avoid running adjoin join or autoupdate operations from affected versions. If automatic machine-account password renewal is enabled, disable it temporarily or ensure renewed passwords are rotated again after upgrading to a fixed version."}],"x_generator":{"engine":"Vulnogram 1.0.5"}}},"cveMetadata":{"assignerOrgId":"df4dee71-de3a-4139-9588-11b62fe6c0ff","assignerShortName":"Fortra","cveId":"CVE-2026-9864","datePublished":"2026-10-01T16:00:25.899Z","dateReserved":"2026-05-28T16:37:54.270Z","dateUpdated":"2026-10-01T16:16:15.483Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-10-01 16:18:09","lastModifiedDate":"2026-10-01 20:34:26","problem_types":["CWE-338","CWE-338 CWE-338 Use of cryptographically weak Pseudo-Random number generator (PRNG)"],"metrics":{"cvssMetricV31":[{"source":"df4dee71-de3a-4139-9588-11b62fe6c0ff","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N","baseScore":4.8,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.2,"impactScore":2.5}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-10-01T16:16:03.897430Z","id":"CVE-2026-9864","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"9864","Ordinal":"1","Title":"Fortra BoKS Server Agent adjoin machine-account password generat","CVE":"CVE-2026-9864","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"9864","Ordinal":"1","NoteData":"Fortra BoKS Server Agent contains a predictable password generation vulnerability in the adjoin utility. Machine-account passwords generated during Active Directory join or password renewal operations may have significantly less entropy than intended, making them more susceptible to prediction by an attacker who can estimate when the password was generated.","Type":"Description","Title":"Fortra BoKS Server Agent adjoin machine-account password generat"}]}}}