Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Critical Flowise RCE Flaws Let Attackers Execute Code on AI Workflow Servers
August 4, 2026
OWASP Releases Subtractive Security Top 10 to Reduce Cyber Risks
August 4, 2026
DarkSword iOS Exploit Kit Spreads to 180 Websites and 27 Hosts
August 4, 2026
Home/CyberSecurity News/Critical StrongDM CVE-2024-2495 Allows Auth Token Theft and Reuse
CyberSecurity News

Critical StrongDM CVE-2024-2495 Allows Auth Token Theft and Reuse

Key Takeaways A severe authentication vulnerability (CVE-2026-4387) was discovered in StrongDM’s desktop applications. The flaw allowed attackers with local system access to steal and reuse...

Marcus Rodriguez
Marcus Rodriguez
June 2, 2026 3 Min Read
49 0

Key Takeaways

  • A severe authentication vulnerability (CVE-2026-4387) was discovered in StrongDM’s desktop applications.
  • The flaw allowed attackers with local system access to steal and reuse authentication tokens, enabling full session hijacking without requiring user credentials.
  • The vulnerability stemmed from plaintext storage of session data, including JWTs and cryptographic keys, in a file accessible with user-level permissions.
  • StrongDM has released patches in Desktop version 23.74.0 and CLI version 53.77.0, which remediate the issue by implementing secure, platform-native storage mechanisms.
  • All StrongDM users are urged to update their clients immediately to protect against potential exploitation.

A critical security vulnerability has been identified in the StrongDM desktop application, posing a significant risk of session hijacking for enterprise users. Discovered by researchers at SpecterOps, the flaw, designated as CVE-2026-4387, allowed attackers to extract and reuse authentication tokens stored locally, thereby gaining unauthorized access to sensitive infrastructure managed through StrongDM.

Table Of Content

  • Key Takeaways
  • Deep Dive into CVE-2026-4387
  • Exploitation and Impact
  • Remediation and Disclosure Timeline
  • What You Should Do

Deep Dive into CVE-2026-4387

The core of the vulnerability lay in StrongDM’s method of storing session data on the local disk. Following a successful user login, the application would save critical authentication material within a file named .sdmstate.kv, located in the user’s directory (e.g., C:Users<username>.sdmstate.kv). This file contained a JSON Web Token (JWT) along with a public and private key pair, all stored in an unencrypted, plaintext format.

Since the .sdmstate.kv file only required standard user-level permissions for access, an attacker who had already achieved system-level access to a compromised machine could easily retrieve this file without needing elevated privileges. SpecterOps demonstrated that this extracted state file could then be transplanted to another machine, allowing the StrongDM client on the new host to automatically authenticate as the legitimate user without any password or MFA challenges.

Exploitation and Impact

The attack scenario involved copying the KV state file from a compromised system to a different host. By replacing this file, even after the StrongDM application had launched, attackers could bypass typical startup-file protections and leverage the victim’s session. This method effectively allowed for full session hijacking, enabling unauthorized access to databases, servers, and cloud resources managed via StrongDM. The lack of proper binding between the session tokens and the original host environment was a key enabler for this cross-system reuse.

Further analysis by SpecterOps revealed additional weaknesses, including a local endpoint at http://127.0.0.1:65220/v2/authentication that exposed JWT tokens when queried with minimal headers, and cached files like data_1 that also held sensitive authentication data. The ease of exploitation, requiring only user-level permissions, significantly lowers the barrier for adversaries, making it particularly dangerous in post-compromise scenarios where an attacker might already have a foothold within an organization’s network.

Remediation and Disclosure Timeline

StrongDM has addressed this critical flaw by fundamentally changing how sensitive authentication data is stored. The updated versions no longer store plaintext authentication material. Instead, they leverage platform-native secure storage mechanisms, such as DPAPI (Data Protection API) on Windows and Keychain on macOS. Furthermore, JWTs are no longer retained within the state.kv file, preventing their reuse across different systems. Security validation confirmed that transferring session files between hosts no longer grants authenticated access.

The vulnerability was initially reported to StrongDM in May 2025. A fix was subsequently implemented in March 2026. According to SpecterOps, public disclosure of CVE-2026-4387 occurred on May 29, 2026, with a broader disclosure following on June 1, 2026.

What You Should Do

  • Immediately Update: All users of StrongDM Desktop and CLI applications must update to the patched versions. Specifically, StrongDM Desktop version 23.74.0 and StrongDM CLI version 53.77.0 or newer.
  • Review Access Controls: Ensure strict access controls are in place for user directories and sensitive files on endpoints where StrongDM clients are installed.
  • Implement Endpoint Detection and Response (EDR): Utilize EDR solutions to monitor for suspicious activity, such as unauthorized access to application state files or unusual network connections from StrongDM client processes.
  • Educate Users: Reinforce best practices for endpoint security and the importance of timely software updates to prevent local exploitation.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackCVEExploitSecurityVulnerability

Share Article

Marcus Rodriguez

Marcus Rodriguez

Marcus is a security researcher and investigative journalist with expertise in vulnerability research, bug bounties, and cloud security. Since 2017, Marcus has been breaking stories on critical vulnerabilities affecting major platforms. His investigative work has led to the disclosure of numerous security flaws and improved defenses across the industry. Marcus is an active participant in bug bounty programs and has been recognized for responsible disclosure practices. He holds multiple security certifications and regularly speaks at industry events.

Previous Post

Critical Android 0-Day CVE-2023-35674 Lets Attackers Control Devices

Next Post

Dashlane Accounts Locked After Brute-Force Attacks

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
New Roblox Malware Steals Desktop Streams and Webcam Footage
August 4, 2026
Keyv npm package compromised in supply chain attack
August 4, 2026
Cybercriminals Exploit ChatGPT for Scam Operations, OpenAI Reports
August 4, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Emy Elsamnoudy
Emy Elsamnoudy
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us