StrongDM A.I CyberSecurity Scoring
StrongDM
Company Information
Website:https://www.strongdm.com
Employees number:124
Number of followers:14,512
NAICS:5112
Industry Type:Software Development
Homepage:strongdm.com
StrongDM Risk Score (AI oriented)
Between 750 and 799
StrongDMSoftware Development
Updated:
02/06/2026
02/06/2026
750/1000
Fair
Baa
StrongDM Global Score (TPRM)
xxxx
StrongDMSoftware Development
Score locked

StrongDMFair
Current Score
750Baa (FAIR)
01000
1 incidents
-2 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
750
MAY 2026
752
Vulnerability
29 May 2026 • StrongDM
StrongDM: Critical StrongDM Vulnerability Allows Attackers to Steal and Reuse Authentication
Critical StrongDM Authentication Flaw Allowed Session Hijacking via Local File Theft
750
CRITICAL-2
STR1780388883
Critical StrongDM Authentication Flaw Allowed Session Hijacking via Local File Theft
A severe vulnerability in StrongDM’s desktop application (CVE-2026-4387) was discovered by SpecterOps, enabling attackers to hijack user sessions by reusing locally stored authentication material. The flaw, present in versions prior to StrongDM Desktop 23.74.0 and CLI 53.77.0, stemmed from insecure storage of session data in a plaintext file (`C:\Users\<username>\.sdm\state.kv`).
The file contained unencrypted JSON Web Tokens (JWTs) and cryptographic key pairs, accessible with only user-level permissions. Attackers could copy this file from a compromised system to another machine, allowing the StrongDM client to authenticate as the victim without credentials. The vulnerability persisted even when the file was replaced after application launch, bypassing protections and exposing weaknesses in the authentication flow.
Additional risks included an exposed local endpoint (`http://127.0.0.1:65220/v2/authentication`) leaking JWTs and cached files storing sensitive data. The lack of host-environment binding for session tokens enabled cross-system reuse, amplifying the threat. Exploitation could grant attackers access to databases, servers, and cloud resources, facilitating lateral movement within enterprise networks.
StrongDM addressed the issue by eliminating plaintext storage of authentication data, transitioning to platform-native secure storage (DPAPI on Windows, Keychain on macOS) and removing JWTs from the `state.kv` file. The vulnerability was reported in May 2025, patched in March 2026, and publicly disclosed on May 29, 2026, with broader details released on June 1, 2026. Security validation confirmed that session file reuse no longer grants unauthorized access.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
APRIL 2026
752
MARCH 2026
752
FEBRUARY 2026
752
JANUARY 2026
752
DECEMBER 2025
752
NOVEMBER 2025
752
OCTOBER 2025
752
SEPTEMBER 2025
752
AUGUST 2025
752
JULY 2025
752
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for StrongDM ??
What was StrongDM's A.I Rankiteo Cyber Score in May 2026 ??
What was StrongDM's A.I Rankiteo Cyber Score in April 2026 ??
What was StrongDM's A.I Rankiteo Cyber Score in March 2026 ??
What was StrongDM's A.I Rankiteo Cyber Score in February 2026 ??
What was StrongDM's A.I Rankiteo Cyber Score in January 2026 ??
What was StrongDM's A.I Rankiteo Cyber Score in December 2025 ??
What was StrongDM's A.I Rankiteo Cyber Score in November 2025 ??
What was StrongDM's A.I Rankiteo Cyber Score in October 2025 ??
What was StrongDM's A.I Rankiteo Cyber Score in September 2025 ??
What was StrongDM's A.I Rankiteo Cyber Score in August 2025 ??
What was StrongDM's A.I Rankiteo Cyber Score in July 2025 ??
What is the average per-incident point impact on StrongDM's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with StrongDM ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view StrongDM's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?