External risk intelligence

BoKS Keytab Predictable Password Generation Vulnerability.

CVE advisorySeverity: CRITICAL (CVSS 9.9)

CVE-2026-79901

The vulnerability exists in BoKS keytab management, which typically operates within internal identity and access management infrastructure. While network-reachable in some enterprise environments, this component is generally isolated from the public internet and sits behind internal network controls, making direct public exposure uncommon.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory concerns a flaw in BoKS keytab management that could allow unauthorized access to Active Directory service accounts. The vulnerability stems from how service account passwords are generated, making them predictable under certain circumstances. Understanding this issue is important for maintaining the security of your identity and access management systems.

  • Predictable passwords allow unauthorized access.
  • Protects sensitive internal service accounts.
  • Confirm relevance and exposure of this system.

Attack Path

How an attacker could exploit the issue

An attacker could gain access to service-account passwords by predicting them from a predictable sequence used by boks_keytabmd. This would require the attacker to know the service principal and have a way to estimate when the password was last changed. If successful, the attacker could then use these passwords to impersonate legitimate services.

  • Network access and service principal knowledge needed.
  • Predictable password generation is the trigger.
  • Compromise of services and data.

Live Threat

Current exploitation, exposure, and threat context

In deployments using BoKS keytab management, a vulnerability allows an attacker who knows a service principal and can estimate the password change time to generate and verify potential Active Directory service-account passwords offline. This could affect the confidentiality and integrity of services relying on these credentials.

  • Service account passwords.
  • Predictable password generation.
  • Compromise of protected services.

Operational Fix

Recommended remediation, mitigation, and detection steps

In deployments using BoKS keytab management, the generation of Active Directory service-account passwords from a predictable sequence poses a risk. This vulnerability is likely to be of concern to identity and access management, platform, and security teams. The immediate priority is to identify all instances of the affected BoKS keytab management component, determine its network reachability and business criticality, and confirm the accountable system owner before planning remediation efforts.

  • Identity and Access Management teams own this issue.
  • Verify BoKS keytab management reachability and criticality.
  • Plan targeted remediation based on risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the boks_keytabmd component used for?

This component is part of BoKS keytab management, a tool used to handle authentication credentials for services. It is specifically responsible for managing Active Directory service-account passwords, ensuring that services can securely authenticate within an identity and access management infrastructure.

How does CVE-2026-79901 create a security weakness?

This vulnerability, classified as CWE-338 (Use of a Cryptographically Weak Pseudo-Random Number Generator), occurs because the system uses a predictable sequence based on the Unix timestamp to create passwords. Because the process is not truly random, an attacker can recreate the same sequence used by the software to guess the resulting passwords.

What does an attacker need to trigger this vulnerability?

An attacker must know the specific service principal name and be able to estimate the time when the password was last changed. Importantly, simply having network access is not enough to compromise an account; the attacker must be able to perform these calculations to generate a list of candidate passwords and verify them offline.

Is my system at risk according to Halo Surface Signal?

Halo Surface Signal indicates that this risk is unlikely for many, as the affected component typically resides within internal identity infrastructure rather than being directly exposed to the public internet. While it might be reachable on some internal networks, it is generally shielded by enterprise network controls.

What steps should I take if I use BoKS keytab management?

Your priority is to locate all deployments of the boks_keytabmd component within your organization. Once identified, work with your identity and security teams to verify whether these instances are reachable over the network and assess their business criticality to help prioritize your next steps for hardening or updates.

References