Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
SolyxImmortal Python Malware Steals Browser Data Passwords Cookies
June 2, 2026
Claude AI Down Globally: Users Report Widespread Service Issues
June 2, 2026
Claude’s GitHub Actions Flaw Compromises Any Repository
June 2, 2026
Home/CyberSecurity News/Critical StrongDM Flaw: Attackers Steal & Reuse Vulnerability Allows
CyberSecurity News

Critical StrongDM Flaw: Attackers Steal & Reuse Vulnerability Allows

A critical authentication flaw has been identified in StrongDM’s desktop application. This vulnerability allows attackers to hijack user sessions by reusing locally stored authentication material,...

Marcus Rodriguez
Marcus Rodriguez
June 2, 2026 3 Min Read
4 0

A critical authentication flaw has been identified in StrongDM’s desktop application. This vulnerability allows attackers to hijack user sessions by reusing locally stored authentication material, potentially exposing sensitive enterprise infrastructure.

The issue, tracked as CVE-2026-4387, was discovered by SpecterOps during a security assessment and has been fixed in StrongDM Desktop version 23.74.0 and CLI version 53.77.0.

The vulnerability originates from how StrongDM stored session data on disk. After a successful login, the application saved authentication material in a file located at C:Users<username>.sdmstate.kv.

This file contained a JSON Web Token (JWT) along with a public and private key pair, all stored in plaintext.

Critical StrongDM Vulnerability

Since the file only required user-level permissions to access, an attacker with system-level access could extract it without elevated privileges.

SpecterOps demonstrated that this state file could be reused to impersonate a legitimate user.

Decoded JWT(source : specterops )
Decoded JWT(source : specterops )

Attackers could copy a KV state file from a compromised system to another machine, allowing the StrongDM client to automatically authenticate as the victim and access infrastructure resources without credentials.

The attack worked reliably even across external hosts by replacing the file after application launch, bypassing startup-file protections and exposing additional weaknesses in the authentication flow.

A local endpoint at http://127.0.0.1:65220/v2/authentication exposed JWT tokens when queried with minimal headers, and cached files such as data_1 also stored sensitive authentication data.

StrongDM Resource Connection(source : specterops )
StrongDM Resource Connection (source : specterops )

The lack of binding between session tokens and the host environment enabled the reuse of authentication material across different systems.

The impact of this vulnerability is significant, as it enables full session hijacking without requiring credentials.

Attackers could access databases, servers, and cloud resources managed through StrongDM and potentially move laterally within enterprise environments.

The fact that only user-level permissions are required lowers the barrier for exploitation, especially in post-compromise scenarios.

StrongDM remediated the issue by removing plaintext storage of sensitive authentication data.

The updated versions now use platform-native secure storage mechanisms such as DPAPI on Windows and Keychain on macOS.

State.kv File Reuse Verification  (source : specterops )
State.kv File Reuse Verification (source : specterops )

Additionally, JWTs are no longer stored in the state.KV file, preventing reuse across systems. Security validation confirmed that transferring session files between hosts no longer results in authenticated access.

The vulnerability was initially reported in May 2025, with a fix implemented in March 2026.

According to SpecterOps, CVE-2026-4387 was publicly disclosed on May 29, 2026, followed by a broader disclosure on June 1, 2026.

Users are strongly advised to update to the latest versions to mitigate any potential risk.

This incident highlights the dangers of insecure local credential storage. It emphasizes the importance of protecting authentication tokens through secure storage and proper session binding to prevent reuse attacks.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackCVEExploitSecurityVulnerability

Share Article

Marcus Rodriguez

Marcus Rodriguez

Marcus is a security researcher and investigative journalist with expertise in vulnerability research, bug bounties, and cloud security. Since 2017, Marcus has been breaking stories on critical vulnerabilities affecting major platforms. His investigative work has led to the disclosure of numerous security flaws and improved defenses across the industry. Marcus is an active participant in bug bounty programs and has been recognized for responsible disclosure practices. He holds multiple security certifications and regularly speaks at industry events.

Previous Post

Android 0-Day Exploited: Attacks Gain Full Vulnerability Complete

Next Post

Dashlane Password Manager Accounts Locked by Brute-Force

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Rising Web App & API Attacks: Are You Blind to AI Rising: Are Join
June 2, 2026
PHANTOMPULSE RAT Compromises Windows via Process Uses Injection
June 2, 2026
Nimbus Manticore APT Delivers Malware via Fake Abuses Recruitment
June 2, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Jennifer sherman
Jennifer sherman
David kimber
David kimber
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Detects Critical MongoDB CVE-

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us