CVE-2026-4387
Severity CVSS v4.0:
LOW
Type:
CWE-312
Cleartext Storage of Sensitive Information
Publication date:
29/05/2026
Last modified:
29/05/2026
Description
StrongDM Desktop Application before 23.74.0 (Desktop Client before 53.77.0) on Microsoft Windows stores authentication state, including a JSON Web Token and asymmetric key material, in cleartext in a per-user state file located at C:\Users\\.sdm\state.kv. The file is protected only by default user-level NTFS permissions.<br />
<br />
<br />
<br />
Exploitation requires local read access to the affected user&#39;s profile directory and additional deployment and execution conditions on the target host.<br />
<br />
<br />
<br />
The condition was reported through coordinated disclosure by Hope Walker (SpecterOps).
Impact
Base Score 4.0
2.00
Severity 4.0
LOW



