Security & Threat Intelligence · 25.07.2026, 15:29 UTC
CVE-2026-4387: StrongDM State File Reuse
| Schweregrad | info |
|---|---|
| CVE | ↗ |
| Kategorie | Security & Threat Intelligence |
| Quelle | SpecterOps ↗ |
| Veröffentlicht | 25.07.2026 UTC |
Sicherheitsmeldung mit Schweregrad noch nicht bewertet. Betroffene Kennungen: CVE-2026-4387. Technische Details im Tab „Originaltext“; empfohlene Schritte in der Checkliste.
TL;DR : An attacker could transfer StrongDM state files, which hold session authentication information, between hosts to provide authenticated sessions. The attacker could reuse state files both inside and outside of the environment where an organization deployed it and requires user-level permissions to access the file. Reusing the state file will result in an authenticated session and access to infrastructure. StrongDM issued CVE-2026-4387and this vulnerability was patched in StrongDM Desktop version 23.74.0 and CLI version 53.77.0.
Synopsis
During an assessment, SpecterOps discovered a way to reuse authentication material for StrongDM’s desktop application. After signing in, the desktop application wrote user authentication material to a state file in the user directory, located at the following path:
C:\Users\<username>\.sdm\state.kv
This state.kv file contained a JSON web token (JWT) along with a private and public key pair. The StrongDM desktop application referenced this file for sessions to determine the authentication for the application. Operators transferred the state file between hosts within the same environment and gained an authenticated session.
To carry the attack further, operators attempted to reuse the state file on an external host. Initial tests where operators deployed a new windows virtual machine (VM), installed StrongDM, and attempted to reuse the state file failed. Upon launching StrongDM, the application appeared to clear the contents of the state file.
SpecterOps suspected that an incorrect host or domain name caused the issue. The …
Maßnahmen
⬇ Als MarkdownVerwandte Beiträge
- info Spline rebuilt its entire 3D editor. Then it handed the keys to Claude Code.
- info USN-8669-1: Linux kernel (NVIDIA) vulnerabilities
- info ContestTrade: A Multi-Agent Trading System Based on Internal Contest Mechanism
- info DeepConvContext: A Multi-Scale Approach to Timeseries Classification in Human Activity Recognition