OCTOBER 6, 2026
Live Feed
Back to database
Case File

CVE-2026-79901

CRITICAL · CVSS 9.9 EPSS 0.27%

Source: NVD + CISA KEV + EPSS · Published 2026-10-01 · Last synced 2026-10-06

CyberRota Analysis

AI-Generated

Deployments utilizing BoKS keytab management are vulnerable due to the generation of Active Directory service-account passwords from a predictable pseudo-random sequence based on the current Unix timestamp. This flaw allows attackers with knowledge of the service principal and an estimated password-change time to reproduce potential passwords and verify them offline, leading to unauthorized access. Organizations using affected versions should prioritize remediation to mitigate the risk of credential compromise.

CVE
CVE-2026-79901
Severity
CRITICAL
CVSS
9.9
EPSS
0.27%

Original NVD Description

In deployments using BoKS keytab management, affected versions of boks_keytabmd generate Active Directory service-account passwords from a predictable pseudo-random sequence seeded with the current Unix timestamp. An attacker who knows the service principal and can estimate the password-change time can reproduce a limited candidate set and verify candidates offline.