CVE-2026-4387: StrongDM State File Reuse
ID: 367b857d-87d6-54f0-bfa0-ec358c86a77c
STIX ID: report--367b857d-87d6-54f0-bfa0-ec358c86a77c
Feed Name: SpecterOps Blog
Threat Score
SpecterOps discovered that StrongDM wrote JWTs and plaintext key material to C:\Users\<username>\.sdm\state.kv, enabling an attacker with user-level access to copy that file to another host and obtain an authenticated StrongDM session as the victim; StrongDM patched this (CVE-2026-4387) by migrating secrets to platform-native stores in Desktop 23.74.0 and CLI 53.77.0.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
