logo

Critical StrongDM Vulnerability Enables Authentication Token Theft

ID: e5d96716-8e31-57be-a420-ddcfabf4e620

STIX ID: report--e5d96716-8e31-57be-a420-ddcfabf4e620

Feed Name: ThreatCluster

Threat Score
73/100

Date Published: 2026-06-02

Date Updated: 2026-06-08

...
...

A critical vulnerability (CVE-2026-4387) in StrongDM desktop and CLI allows local extraction and reuse of authentication tokens, enabling session hijacking; it affects StrongDM Desktop versions prior to 23.74.0 and CLI versions prior to 53.77.0 and has been patched — organizations should apply the updates immediately and monitor for unusual authentication activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.