Threat reportVulnerabilityTL-2026-2892

Forgeable Session Cookie (Hard-Coded HMAC Secret) in Yard Management System Bypasses Entra ID MFA and Enables User and Admin Impersonation

highTRACKING

Forgeable Session Cookie (Hard-Coded HMAC Secret) in Yard (TL-2026-2892) is a high-severity software vulnerability, first published 2026-10-02 and last reviewed 2026-10-05. It has no confirmed attribution, affects Unnamed (not disclosed) Supply-chain Yard Management System (YMS), maps to 9 MITRE ATT&CK techniques (T1078.004, T1087, T1190), and is covered by 9 detection rules and 15 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
0None referenced
Techniques
9MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
15Indicators of compromise

Key facts for TL-2026-2892

Threat ID
TL-2026-2892
Severity
HIGH
Status
TRACKING
Category
VULNERABILITY
First published
Last reviewed
Attribution confidence
LOW
Motivation
UNKNOWN
Target sectors
logistics, supply-chain, transport, manufacturing
Target regions
Global
Detection rules
9
Indicators of compromise
15
Updates
2026-10-05 · revalidated 1× · latest source

How Forgeable Session Cookie (Hard-Coded HMAC Secret) in Yard works

Resecurity found that a supply-chain yard management system (YMS) signed its custom session cookie with a hard-coded HMAC secret identical to the cookie name, and the signed value was a user's publicly exposed database identifier (CUID). An unauthenticated attacker could forge sessions for arbitrary users, including administrators, without a password, fresh MFA approval, or Entra ID token; 95 of 241 tested accounts were impersonated during an authorized assessment.

Resecurity identified the weakness during authorized testing of a staging deployment of a yard management system (YMS) platform used to coordinate supply-chain and yard operations. The application used Microsoft Entra ID (MSAL) single sign-on with MFA for login, but after authentication it relied on a custom signed-session cookie named session_secret_example. The cookie has the form s:<payload>.<signature> (URL-encoded), with an HMAC-SHA256 signature produced via the Node.js cookie-signature library. The signing secret was the literal string session_secret_example, identical to the cookie name, and was recovered by an offline search of roughly 110 candidate values against known payload/signature pairs.

The signed payload was not a random server-side session identifier but the user's database identifier (CUID), which the application exposed publicly. CUIDs were obtainable from the authenticated-user endpoint /api/v1/auth/me, user list/detail endpoints, createdBy/updatedBy fields in API responses, the /admin/lookups/app-users and /admin/lookups/employee-users directory endpoints, and the login role/type selection flow. Knowing a target CUID and the secret, an attacker could mint a valid cookie for that user; neither value should have been sufficient to establish an authenticated session. Both the API and the Next.js administrative SPA accepted the forged sessions, so the Entra ID SSO/MFA step was never enforced on the forged path. The flaw is in the custom application session layer, not in Microsoft Entra ID itself.

Impact was demonstrated by impersonating 95 of 241 tested user IDs, including elevated accounts (a Yard Marshall, a Technician and a SUPER_USER were shown returning HTTP 200), and by a forged administrator session performing a state-changing API request whose changes persisted in staging (test records were restored afterward). Additional exposure: the /api/v1/auth/me response returned the authenticated user's Entra refresh token, and an unauthenticated Swagger UI at /api-docs/ exposed the full 251-route API surface. Reported stack: Node.js/Express, express-openapi-validator, Next.js, Prisma/PostgreSQL, MSAL. No CVE, CVSS score, vendor name, or in-the-wild exploitation was reported; severity is analyst-assigned.

MITRE ATT&CK techniques used in TL-2026-2892

Initial Access

T1078.004 Valid Accounts: Cloud Accounts; T1190 Exploit Public-Facing Application

Discovery

T1087 Account Discovery

Credential Access

T1212 Exploitation for Credential Access; T1528 Steal Application Access Token; T1606.001 Forge Web Credentials: Web Cookies

lateral-movement

T1550.004 Use Alternate Authentication Material: Web Session Cookie

Impact

T1565.001 Data Manipulation: Stored Data Manipulation

Reconnaissance

T1589 Gather Victim Identity Information

Affected products and versions in Forgeable Session Cookie (Hard-Coded HMAC Secret) in Yard

  • Unnamed (not disclosed) — Supply-chain Yard Management System (YMS) platform with custom signed-session-cookie auth and Entra ID SSO
    Vulnerable versions: Assessed staging deployment (version not disclosed)

Remediation for Forgeable Session Cookie (Hard-Coded HMAC Secret) in Yard

Immediate actions

  • Rotate the session-signing secret immediately (e.g. openssl rand -base64 48)
  • Invalidate all active sessions and refresh tokens
  • Remove Entra refresh tokens from /api/v1/auth/me and other API responses
  • Review authentication logs for unauthorized session creation, impersonation, token exposure and administrative activity

Workarounds

  • Block or alert on requests presenting the session_secret_example cookie until the secret is rotated

Longer-term hardening

  • Replace self-contained identity-bearing cookies with random server-side session identifiers (e.g. Redis-backed session store)
  • Use separate high-entropy secrets for each environment
  • Enforce short session lifetimes
  • Bind sensitive actions to step-up authentication
  • Restrict or authenticate the Swagger/OpenAPI interface at /api-docs/

Weaknesses (CWE) in Forgeable Session Cookie (Hard-Coded HMAC Secret) in Yard

CWE-798, CWE-327, CWE-287

Timeline of Forgeable Session Cookie (Hard-Coded HMAC Secret) in Yard

  • Varonis publishes Cookie-Bite research on session-cookie theft bypassing Entra ID MFA (related, distinct technique: cookie theft rather than forgery)
  • Resecurity describes the finding as a coordinated vulnerability disclosure to the vendor; a Python proof-of-concept that forges the cookie for a target CUID is published. No CVE or public vendor advisory identified.
  • Resecurity publishes 'Session Cookie Authentication Bypass: Predictable Signing Secret Enables Account Impersonation' on its blog
  • Findings also show /api/v1/auth/me returning the user's Entra refresh token and an unauthenticated Swagger UI at /api-docs/ exposing 251 routes
  • Forged cookies impersonate 95 of 241 tested user IDs, including a Yard Marshall, Technician and SUPER_USER; forged admin session performs a persisted state-changing API request (test records restored)
  • Resecurity identifies the forgeable session cookie flaw during authorized testing of a YMS staging environment; HMAC secret recovered by offline search of ~110 candidates
  • Cyber Security News, GBHackers and Cryptika publish coverage; no CVE, vendor name, patch or in-the-wild exploitation reported

Update history for TL-2026-2892

Sources cited for Forgeable Session Cookie (Hard-Coded HMAC Secret) in Yard

Detection coverage for TL-2026-2892

As of 2026-10-05, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2892 across Splunk SPL, Microsoft KQL and Sigma, covering 15 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
15 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats