StrongDM Desktop Application before 23.74.0 (Desktop Client before 53.77.0) on Microsoft Windows stores authentication state, including a JSON Web Token and asymmetric key material, in cleartext in a per-user state file located at C:\Users\<username>\.sdm\state.kv. The file is protected only by default user-level NTFS permissions.



Exploitation requires local read access to the affected user's profile directory and additional deployment and execution conditions on the target host.



The condition was reported through coordinated disclosure by Hope Walker (SpecterOps).

Project Subscriptions

No data.

Advisories

No advisories yet.

Fixes

Solution

Upgrade the StrongDM Desktop Application to version 23.74.0 or later (Desktop Client 53.77.0 or later). The fixed release protects the state.kv file at rest using a platform-native data-protection mechanism (Windows DPAPI on Windows).


Workaround

No workaround given by the vendor.

History

Fri, 29 May 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 29 May 2026 19:30:00 +0000

Type Values Removed Values Added
Description StrongDM Desktop Application before 23.74.0 (Desktop Client before 53.77.0) on Microsoft Windows stores authentication state, including a JSON Web Token and asymmetric key material, in cleartext in a per-user state file located at C:\Users\<username>\.sdm\state.kv. The file is protected only by default user-level NTFS permissions. Exploitation requires local read access to the affected user's profile directory and additional deployment and execution conditions on the target host. The condition was reported through coordinated disclosure by Hope Walker (SpecterOps).
Title Unencrypted storage of authentication state in StrongDM Desktop Application state.kv file
Weaknesses CWE-312
CWE-522
References
Metrics cvssV4_0

{'score': 2, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:L/SI:L/SA:L'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: StrongDM

Published:

Updated: 2026-05-29T19:49:33.218Z

Reserved: 2026-03-18T13:52:47.802Z

Link: CVE-2026-4387

cve-icon Vulnrichment

Updated: 2026-05-29T19:49:25.134Z

cve-icon NVD

Status : Received

Published: 2026-05-29T20:16:30.650

Modified: 2026-05-29T20:16:30.650

Link: CVE-2026-4387

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-29T20:30:07Z

Weaknesses