CVE-2026-9864
Der Fortra BoKS Server Agent enthält eine Schwachstelle bei der vorhersehbaren Passworterzeugung in der adjoin-Utility.
mediumEPSS 0.2%
Description
Fortra BoKS Server Agent contains a predictable password generation vulnerability in the adjoin utility. Machine-account passwords generated during Active Directory join or password renewal operations may have significantly less entropy than intended, making them more susceptible to prediction by an attacker who can estimate when the password was generated.
Source: NVD (NIST)cvelistv5
Metrics
Show all metrics
Severity
medium
54.09
no public PoC known
4.8
Published
2026-10-01 16:00 UTC
CWE-338
Weakness classes (CWE)
CWE-338Base
Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)
The product uses a Pseudo-Random Number Generator (PRNG) in a security context, but the PRNG's algorithm is not cryptographically strong.
cwe.mitre.org →
References & sources
Reanalysis & status changes
Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.
- CVE Modified2026-10-01 17:17 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
- SSVC: {"id":"CVE-2026-9864","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalIm…
- New CVE Received2026-10-01 16:18 UTC· df4dee71-de3a-4139-9588-11b62fe6c0ff
- Description: Fortra BoKS Server Agent contains a predictable password generation vulnerability in the adjoin utility. Machine-account passwords generated during Active Directory join or password renewal operations may have significantly less entropy than intended, making them more susceptible to prediction by an attacker who can estimate when the password was generated.
- CVSS V3.1: AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
- CWE: CWE-338
- Affected: New affected value received. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/9xxx/CVE-2026-9864.json">CVE-2026-9864</a>