logo

CVE-2026-4387: StrongDM State File Reuse

ID: 367b857d-87d6-54f0-bfa0-ec358c86a77c

STIX ID: report--367b857d-87d6-54f0-bfa0-ec358c86a77c

Feed Name: SpecterOps Blog

Threat Score
70/100

Date Published: 2026-06-01

Date Updated: 2026-06-03

...
...

SpecterOps discovered that StrongDM wrote JWTs and plaintext key material to C:\Users\<username>\.sdm\state.kv, enabling an attacker with user-level access to copy that file to another host and obtain an authenticated StrongDM session as the victim; StrongDM patched this (CVE-2026-4387) by migrating secrets to platform-native stores in Desktop 23.74.0 and CLI 53.77.0.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.