{"id":"CVE-2026-9864","title":"Fortra BoKS Server Agent contains a predictable password generation vulnerability in the adjoin utility","summary":"Fortra BoKS Server Agent contains a predictable password generation vulnerability in the adjoin utility. Machine-account passwords generated during Active Directory join or password renewal operations may have significantly less entropy …","severity":"medium","cvss":4.8,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N","cwe":["CWE-338"],"vendor":"Fortra","product":"Core Privileged Access Manager (BoKS)","affected":["core_privileged_access_manager_boks >= 8.1.0.0 <= 8.1.0.29","core_privileged_access_manager_boks >= 9.0.0.0 <= 9.0.0.5"],"published":"2026-10-01","updated":"2026-10-01","sourceUpdated":"2026-10-01T20:34:26.287","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-9864","references":[{"url":"https://www.fortra.com/security/advisories/product-security/fi-2026-018","label":"df4dee71-de3a-4139-9588-11b62fe6c0ff"}],"tags":["nvd","cve.org"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-10-01T16:16:03.897430Z"},"ingestedAt":"2026-10-01T18:55:42.357Z","slug":"CVE-2026-9864","body":"## Overview\n\nFortra BoKS Server Agent contains a predictable password generation vulnerability in the adjoin utility. Machine-account passwords generated during Active Directory join or password renewal operations may have significantly less entropy than intended, making them more susceptible to prediction by an attacker who can estimate when the password was generated.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":26,"depthScoreParts":{"impact":26.4,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}