CVE-2026-4387 Details
Description
StrongDM Desktop Application before 23.74.0 (Desktop Client before 53.77.0) on Microsoft Windows stores authentication state, including a JSON Web Token and asymmetric key material, in cleartext in a per-user state file located at C:\Users\<username>\.sdm\state.kv. The file is protected only by default user-level NTFS permissions. Exploitation requires local read access to the affected user's profile directory and additional deployment and execution conditions on the target host. The condition was reported through coordinated disclosure by Hope Walker (SpecterOps).
A vulnerability exists in the StrongDM Desktop Application for Windows, all versions prior to 23.74.0, and the StrongDM Desktop Client, all versions prior to 53.77.0. These applications store authentication state, including a JSON Web Token and asymmetric key material, in cleartext within a per-user state file located at C:\Users\<username>\.sdm\state.kv. This file is only protected by default user-level NTFS permissions. Exploitation of this vulnerability requires local read access to the affected user's profile directory, along with additional deployment and execution conditions on the target host.
Users should update to StrongDM Desktop Application version 23.74.0 or StrongDM Desktop Client version 53.77.0 or later.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No CVSS 3.x data is available for this CVE.
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 29, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://security.strongdm.com/?tcuUid=56fde839-9388-4361-8d3b-9baa7b2de2ed | StrongDM | |
| https://specterops.io/blog/2026/06/01/cve-2026-4387-strongdm-state-file-reuse/ | StrongDM |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-312 | Cleartext Storage of Sensitive Information | StrongDM |
| CWE-522 | Insufficiently Protected Credentials | StrongDM |
Affected Products
No affected product data is available for this CVE.
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 22, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | StrongDM |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 1, 2026 | CVE Modified | StrongDM |
| May 29, 2026 | New CVE Received | StrongDM |