Threat reportVulnerabilityTL-2026-2892
Forgeable Session Cookie (Hard-Coded HMAC Secret) in Yard Management System Bypasses Entra ID MFA and Enables User and Admin Impersonation
Forgeable Session Cookie (Hard-Coded HMAC Secret) in Yard (TL-2026-2892) is a high-severity software vulnerability, first published 2026-10-02 and last reviewed 2026-10-05. It has no confirmed attribution, affects Unnamed (not disclosed) Supply-chain Yard Management System (YMS), maps to 9 MITRE ATT&CK techniques (T1078.004, T1087, T1190), and is covered by 9 detection rules and 15 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 9MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 15Indicators of compromise
Key facts for TL-2026-2892
- Threat ID
- TL-2026-2892
- Severity
- HIGH
- Status
- TRACKING
- Category
- VULNERABILITY
- First published
- Last reviewed
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Target sectors
- logistics, supply-chain, transport, manufacturing
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 15
- Updates
- 2026-10-05 · revalidated 1× · latest source
How Forgeable Session Cookie (Hard-Coded HMAC Secret) in Yard works
Resecurity found that a supply-chain yard management system (YMS) signed its custom session cookie with a hard-coded HMAC secret identical to the cookie name, and the signed value was a user's publicly exposed database identifier (CUID). An unauthenticated attacker could forge sessions for arbitrary users, including administrators, without a password, fresh MFA approval, or Entra ID token; 95 of 241 tested accounts were impersonated during an authorized assessment.
Resecurity identified the weakness during authorized testing of a staging deployment of a yard management system (YMS) platform used to coordinate supply-chain and yard operations. The application used Microsoft Entra ID (MSAL) single sign-on with MFA for login, but after authentication it relied on a custom signed-session cookie named session_secret_example. The cookie has the form s:<payload>.<signature> (URL-encoded), with an HMAC-SHA256 signature produced via the Node.js cookie-signature library. The signing secret was the literal string session_secret_example, identical to the cookie name, and was recovered by an offline search of roughly 110 candidate values against known payload/signature pairs.
The signed payload was not a random server-side session identifier but the user's database identifier (CUID), which the application exposed publicly. CUIDs were obtainable from the authenticated-user endpoint /api/v1/auth/me, user list/detail endpoints, createdBy/updatedBy fields in API responses, the /admin/lookups/app-users and /admin/lookups/employee-users directory endpoints, and the login role/type selection flow. Knowing a target CUID and the secret, an attacker could mint a valid cookie for that user; neither value should have been sufficient to establish an authenticated session. Both the API and the Next.js administrative SPA accepted the forged sessions, so the Entra ID SSO/MFA step was never enforced on the forged path. The flaw is in the custom application session layer, not in Microsoft Entra ID itself.
Impact was demonstrated by impersonating 95 of 241 tested user IDs, including elevated accounts (a Yard Marshall, a Technician and a SUPER_USER were shown returning HTTP 200), and by a forged administrator session performing a state-changing API request whose changes persisted in staging (test records were restored afterward). Additional exposure: the /api/v1/auth/me response returned the authenticated user's Entra refresh token, and an unauthenticated Swagger UI at /api-docs/ exposed the full 251-route API surface. Reported stack: Node.js/Express, express-openapi-validator, Next.js, Prisma/PostgreSQL, MSAL. No CVE, CVSS score, vendor name, or in-the-wild exploitation was reported; severity is analyst-assigned.
MITRE ATT&CK techniques used in TL-2026-2892
Initial Access
T1078.004 Valid Accounts: Cloud Accounts; T1190 Exploit Public-Facing Application
Discovery
Credential Access
T1212 Exploitation for Credential Access; T1528 Steal Application Access Token; T1606.001 Forge Web Credentials: Web Cookies
lateral-movement
T1550.004 Use Alternate Authentication Material: Web Session Cookie
Impact
T1565.001 Data Manipulation: Stored Data Manipulation
Reconnaissance
Affected products and versions in Forgeable Session Cookie (Hard-Coded HMAC Secret) in Yard
- Unnamed (not disclosed) — Supply-chain Yard Management System (YMS) platform with custom signed-session-cookie auth and Entra ID SSO
Vulnerable versions: Assessed staging deployment (version not disclosed)
Remediation for Forgeable Session Cookie (Hard-Coded HMAC Secret) in Yard
Immediate actions
- Rotate the session-signing secret immediately (e.g. openssl rand -base64 48)
- Invalidate all active sessions and refresh tokens
- Remove Entra refresh tokens from /api/v1/auth/me and other API responses
- Review authentication logs for unauthorized session creation, impersonation, token exposure and administrative activity
Workarounds
- Block or alert on requests presenting the session_secret_example cookie until the secret is rotated
Longer-term hardening
- Replace self-contained identity-bearing cookies with random server-side session identifiers (e.g. Redis-backed session store)
- Use separate high-entropy secrets for each environment
- Enforce short session lifetimes
- Bind sensitive actions to step-up authentication
- Restrict or authenticate the Swagger/OpenAPI interface at /api-docs/
Weaknesses (CWE) in Forgeable Session Cookie (Hard-Coded HMAC Secret) in Yard
Timeline of Forgeable Session Cookie (Hard-Coded HMAC Secret) in Yard
- Varonis publishes Cookie-Bite research on session-cookie theft bypassing Entra ID MFA (related, distinct technique: cookie theft rather than forgery)
- Resecurity describes the finding as a coordinated vulnerability disclosure to the vendor; a Python proof-of-concept that forges the cookie for a target CUID is published. No CVE or public vendor advisory identified.
- Resecurity publishes 'Session Cookie Authentication Bypass: Predictable Signing Secret Enables Account Impersonation' on its blog
- Findings also show /api/v1/auth/me returning the user's Entra refresh token and an unauthenticated Swagger UI at /api-docs/ exposing 251 routes
- Forged cookies impersonate 95 of 241 tested user IDs, including a Yard Marshall, Technician and SUPER_USER; forged admin session performs a persisted state-changing API request (test records restored)
- Resecurity identifies the forgeable session cookie flaw during authorized testing of a YMS staging environment; HMAC secret recovered by offline search of ~110 candidates
- Cyber Security News, GBHackers and Cryptika publish coverage; no CVE, vendor name, patch or in-the-wild exploitation reported
Update history for TL-2026-2892
- 2026-10-05 — Authentication Bypass in Yard Management System (YMS) Platform Allows Impersonation of 95 Users Without Passwords or MFA via Forged Session Cookies (Hard-Coded HMAC Secret): What changed No severity, exploitability or status change; the newer report's CRITICAL/ACTIVE labels are restatements of identical facts with no new evidence (no in-the-wild exploitation, no CVSS), so existing values are kept. New indicator
Sources cited for Forgeable Session Cookie (Hard-Coded HMAC Secret) in Yard
- Session Cookie Authentication Bypass: Predictable Signing Secret Enables Account Impersonation (Resecurity)
- Session Cookie Vulnerability Lets Attackers Bypass Entra ID MFA and Impersonate Users (Cyber Security News)
- Authentication Bypass Successfully Impersonated 95 Users Without Passwords or MFA (GBHackers)
- Session Cookie Vulnerability Lets Attackers Bypass Entra ID MFA and Impersonate Users (Cryptika)
- Predictable Session Cookie Secret Enabled Entra MFA Bypass and Account Impersonation (Mallory)
- MITRE ATT&CK T1550.004 Use Alternate Authentication Material: Web Session Cookie
- MITRE ATT&CK T1606.001 Forge Web Credentials: Web Cookies
- Cookie-Bite: How Your Digital Crumbs Let Threat Actors Bypass MFA (Varonis, related session-cookie MFA bypass)
Detection coverage for TL-2026-2892
As of 2026-10-05, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2892 across Splunk SPL, Microsoft KQL and Sigma, covering 15 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.