Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-79901

Опубликовано: 01 окт. 2026
Источник: nvd
CVSS3: 9.9
EPSS Низкий

Описание

In deployments using BoKS keytab management, affected versions of boks_keytabmd generate Active Directory service-account passwords from a predictable pseudo-random sequence seeded with the current Unix timestamp. An attacker who knows the service principal and can estimate the password-change time can reproduce a limited candidate set and verify candidates offline.

EPSS

Процентиль: 17%
0.00266
Низкий

9.9 Critical

CVSS3

Дефекты

CWE-338

Связанные уязвимости

CVSS3: 9.9
github
2 дня назад

In deployments using BoKS keytab management, affected versions of boks_keytabmd generate Active Directory service-account passwords from a predictable pseudo-random sequence seeded with the current Unix timestamp. An attacker who knows the service principal and can estimate the password-change time can reproduce a limited candidate set and verify candidates offline.

EPSS

Процентиль: 17%
0.00266
Низкий

9.9 Critical

CVSS3

Дефекты

CWE-338