CVE-2026-9864
MEDIUM
4,8
Source: df4dee71-de3a-4139-9588-11b62fe6c0ff
Attack Vector: network
Attack Complexity: high
Privileges Required: none
User Interaction: none
Scope: unchanged
Confidentiality: low
Integrity: low
Availability: none
Description
AI Translation Available
Fortra BoKS Server Agent contains a predictable password generation vulnerability in the adjoin utility. Machine-account passwords generated during Active Directory join or password renewal operations may have significantly less entropy than intended, making them more susceptible to prediction by an attacker who can estimate when the password was generated.
338
Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)
DraftCommon Consequences
Security Scopes Affected:
Access Control
Potential Impacts:
Bypass Protection Mechanism
Applicable Platforms
All platforms may be affected
https://www.fortra.com/security/advisories/product-security/fi-2026-018