CVE-2026-9864

Der Fortra BoKS Server Agent enthält eine Schwachstelle bei der vorhersehbaren Passworterzeugung in der adjoin-Utility.

mediumEPSS 0.2%

Description

Fortra BoKS Server Agent contains a predictable password generation vulnerability in the adjoin utility. Machine-account passwords generated during Active Directory join or password renewal operations may have significantly less entropy than intended, making them more susceptible to prediction by an attacker who can estimate when the password was generated.

Metrics

4.8
Source: cna-v3
3.3 %
Low — this CVE sits in the lower 10% of all CVEs scored today.
Show all metrics
Severity
medium
no public PoC known
0.2 %
Low — model estimates < 1% exploitation likelihood.
Published
2026-10-01 16:00 UTC
CWE-338

Weakness classes (CWE)

  • CWE-338Base

    Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)

    The product uses a Pseudo-Random Number Generator (PRNG) in a security context, but the PRNG's algorithm is not cryptographically strong.

    cwe.mitre.org →

References & sources

Reanalysis & status changes

Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.

  1. CVE Modified2026-10-01 17:17 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
    • SSVC: {"id":"CVE-2026-9864","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalIm…
  2. New CVE Received2026-10-01 16:18 UTC· df4dee71-de3a-4139-9588-11b62fe6c0ff
    • Description: Fortra BoKS Server Agent contains a predictable password generation vulnerability in the adjoin utility. Machine-account passwords generated during Active Directory join or password renewal operations may have significantly less entropy than intended, making them more susceptible to prediction by an attacker who can estimate when the password was generated.
    • CVSS V3.1: AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
    • CWE: CWE-338
    • Affected: New affected value received. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/9xxx/CVE-2026-9864.json">CVE-2026-9864</a>