CVE-2026-79901
CRITICAL
NVD
CVSS Score
9.9
Severity
CRITICAL
Published
Oct 01, 2026
Vendor
unknown
Description
In deployments using BoKS keytab management, affected versions of boks_keytabmd generate Active Directory service-account passwords from a predictable pseudo-random sequence seeded with the current Unix timestamp. An attacker who knows the service principal and can estimate the password-change time can reproduce a limited candidate set and verify candidates offline.