Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
StrongDM

StrongDM Vendor Cyber Rating & Cyber Score

strongdm.com

Now part of Delinea | March 2026 StrongDM is the universal access management company reimagining privileged access management. Built for enterprises managing explosive growth in both human and machine identities, StrongDM provides real-time authorization enforcement that governs privileged actions across infrastructure, applications, and cloud environments — not just initial access. The platform unifies traditional PAM capabilities with advanced authorization controls, evaluating identity, context, and policy to authorize or block every privileged operation. Security teams gain action-level visibility and control, while end users experience frictionless access. StrongDM enables organizations to evolve toward continuous, context-aware


StrongDM A.I CyberSecurity Scoring

StrongDM
Company Information
Website:https://www.strongdm.com
Employees number:124
Number of followers:14,512
NAICS:5112
Industry Type:Software Development
Homepage:strongdm.com
StrongDM Risk Score (AI oriented)
Between 750 and 799
logo
StrongDMSoftware Development
Updated:
02/06/2026
750/1000
Fair
Baa
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
StrongDM Global Score (TPRM)
xxxx
logo
StrongDMSoftware Development
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

StrongDM
StrongDMFair
Current Score
750Baa (FAIR)
01000
1 incidents
-2 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
750Before Incident
MAY 2026
752Before Incident
Vulnerability
29 May 2026StrongDM
StrongDM: Critical StrongDM Vulnerability Allows Attackers to Steal and Reuse Authentication

Critical StrongDM Authentication Flaw Allowed Session Hijacking via Local File Theft

750After Incident
CRITICAL-2
STR1780388883
Critical StrongDM Authentication Flaw Allowed Session Hijacking via Local File Theft A severe vulnerability in StrongDM’s desktop application (CVE-2026-4387) was discovered by SpecterOps, enabling attackers to hijack user sessions by reusing locally stored authentication material. The flaw, present in versions prior to StrongDM Desktop 23.74.0 and CLI 53.77.0, stemmed from insecure storage of session data in a plaintext file (`C:\Users\<username>\.sdm\state.kv`). The file contained unencrypted JSON Web Tokens (JWTs) and cryptographic key pairs, accessible with only user-level permissions. Attackers could copy this file from a compromised system to another machine, allowing the StrongDM client to authenticate as the victim without credentials. The vulnerability persisted even when the file was replaced after application launch, bypassing protections and exposing weaknesses in the authentication flow. Additional risks included an exposed local endpoint (`http://127.0.0.1:65220/v2/authentication`) leaking JWTs and cached files storing sensitive data. The lack of host-environment binding for session tokens enabled cross-system reuse, amplifying the threat. Exploitation could grant attackers access to databases, servers, and cloud resources, facilitating lateral movement within enterprise networks. StrongDM addressed the issue by eliminating plaintext storage of authentication data, transitioning to platform-native secure storage (DPAPI on Windows, Keychain on macOS) and removing JWTs from the `state.kv` file. The vulnerability was reported in May 2025, patched in March 2026, and publicly disclosed on May 29, 2026, with broader details released on June 1, 2026. Security validation confirmed that session file reuse no longer grants unauthorized access.
INCIDENT DETAILS -
TYPE
Authentication Flaw
IMPACT
Data Compromised: Session tokens (JWTs), cryptographic key pairs, sensitive cached dataSystems Affected: StrongDM Desktop (versions prior to 23.74.0), StrongDM CLI (versions prior to 53.77.0)Operational Impact: Unauthorized access to databases, servers, and cloud resources; lateral movement within enterprise networksIdentity Theft Risk: High (due to session hijacking and access to sensitive resources)
DATA BREACH
Type Of Data Compromised: Session tokens (JWTs), cryptographic key pairs, sensitive cached dataSensitivity Of Data: High (authentication material enabling unauthorized access)Data Encryption: No (plaintext storage)JSON Web Tokens (JWTs)Cryptographic key pairsCached sensitive data
APRIL 2026
752Before Incident
MARCH 2026
752Before Incident
FEBRUARY 2026
752Before Incident
JANUARY 2026
752Before Incident
DECEMBER 2025
752Before Incident
NOVEMBER 2025
752Before Incident
OCTOBER 2025
752Before Incident
SEPTEMBER 2025
752Before Incident
AUGUST 2025
752Before Incident
JULY 2025
752Before Incident

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for StrongDM ?
?
What was StrongDM's A.I Rankiteo Cyber Score in May 2026 ?
?
What was StrongDM's A.I Rankiteo Cyber Score in April 2026 ?
?
What was StrongDM's A.I Rankiteo Cyber Score in March 2026 ?
?
What was StrongDM's A.I Rankiteo Cyber Score in February 2026 ?
?
What was StrongDM's A.I Rankiteo Cyber Score in January 2026 ?
?
What was StrongDM's A.I Rankiteo Cyber Score in December 2025 ?
?
What was StrongDM's A.I Rankiteo Cyber Score in November 2025 ?
?
What was StrongDM's A.I Rankiteo Cyber Score in October 2025 ?
?
What was StrongDM's A.I Rankiteo Cyber Score in September 2025 ?
?
What was StrongDM's A.I Rankiteo Cyber Score in August 2025 ?
?
What was StrongDM's A.I Rankiteo Cyber Score in July 2025 ?
?
What is the average per-incident point impact on StrongDM's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with StrongDM ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view StrongDM's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?