Exploitation requires local read access to the affected user's profile directory and additional deployment and execution conditions on the target host.
The condition was reported through coordinated disclosure by Hope Walker (SpecterOps).
Project Subscriptions
No data.
No advisories yet.
Solution
Upgrade the StrongDM Desktop Application to version 23.74.0 or later (Desktop Client 53.77.0 or later). The fixed release protects the state.kv file at rest using a platform-native data-protection mechanism (Windows DPAPI on Windows).
Workaround
No workaround given by the vendor.
Fri, 29 May 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 29 May 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | StrongDM Desktop Application before 23.74.0 (Desktop Client before 53.77.0) on Microsoft Windows stores authentication state, including a JSON Web Token and asymmetric key material, in cleartext in a per-user state file located at C:\Users\<username>\.sdm\state.kv. The file is protected only by default user-level NTFS permissions. Exploitation requires local read access to the affected user's profile directory and additional deployment and execution conditions on the target host. The condition was reported through coordinated disclosure by Hope Walker (SpecterOps). | |
| Title | Unencrypted storage of authentication state in StrongDM Desktop Application state.kv file | |
| Weaknesses | CWE-312 CWE-522 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: StrongDM
Published:
Updated: 2026-05-29T19:49:33.218Z
Reserved: 2026-03-18T13:52:47.802Z
Link: CVE-2026-4387
Updated: 2026-05-29T19:49:25.134Z
Status : Received
Published: 2026-05-29T20:16:30.650
Modified: 2026-05-29T20:16:30.650
Link: CVE-2026-4387
No data.
OpenCVE Enrichment
Updated: 2026-05-29T20:30:07Z