# Forgeable Session Cookie (Hard-Coded HMAC Secret) in Yard Management System Bypasses Entra ID MFA and Enables User and Admin Impersonation

> Resecurity found that a supply-chain yard management system (YMS) signed its custom session cookie with a hard-coded HMAC secret identical to the cookie name, and the signed value was a user's publicly exposed database identifier (CUID). An unauthenticated attacker could forge sessions for arbitrary users, including administrators, without a password, fresh MFA approval, or Entra ID token; 95 of 241 tested accounts were impersonated during an authorized assessment.

- **Published:** 2026-10-02T00:00:00Z
- **Last reviewed:** 2026-10-05T03:21:35.970Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-2892
- **ID:** TL-2026-2892
- **Severity:** HIGH
- **Category:** VULNERABILITY
- **Status:** TRACKING
- **Detections:** 9 · **IOCs:** 15 (full data via the Threadlinqs MCP server — Purple tier)

## Description

Resecurity identified the weakness during authorized testing of a staging deployment of a yard management system (YMS) platform used to coordinate supply-chain and yard operations. The application used Microsoft Entra ID (MSAL) single sign-on with MFA for login, but after authentication it relied on a custom signed-session cookie named session_secret_example. The cookie has the form s:<payload>.<signature> (URL-encoded), with an HMAC-SHA256 signature produced via the Node.js cookie-signature library. The signing secret was the literal string session_secret_example, identical to the cookie name, and was recovered by an offline search of roughly 110 candidate values against known payload/signature pairs.

The signed payload was not a random server-side session identifier but the user's database identifier (CUID), which the application exposed publicly. CUIDs were obtainable from the authenticated-user endpoint /api/v1/auth/me, user list/detail endpoints, createdBy/updatedBy fields in API responses, the /admin/lookups/app-users and /admin/lookups/employee-users directory endpoints, and the login role/type selection flow. Knowing a target CUID and the secret, an attacker could mint a valid cookie for that user; neither value should have been sufficient to establish an authenticated session. Both the API and the Next.js administrative SPA accepted the forged sessions, so the Entra ID SSO/MFA step was never enforced on the forged path. The flaw is in the custom application session layer, not in Microsoft Entra ID itself.

Impact was demonstrated by impersonating 95 of 241 tested user IDs, including elevated accounts (a Yard Marshall, a Technician and a SUPER_USER were shown returning HTTP 200), and by a forged administrator session performing a state-changing API request whose changes persisted in staging (test records were restored afterward). Additional exposure: the /api/v1/auth/me response returned the authenticated user's Entra refresh token, and an unauthenticated Swagger UI at /api-docs/ exposed the full 251-route API surface. Reported stack: Node.js/Express, express-openapi-validator, Next.js, Prisma/PostgreSQL, MSAL. No CVE, CVSS score, vendor name, or in-the-wild exploitation was reported; severity is analyst-assigned.

## MITRE ATT&CK

- T1190 Exploit Public-Facing Application
- T1078.004 Valid Accounts: Cloud Accounts
- T1606.001 Forge Web Credentials: Web Cookies
- T1212 Exploitation for Credential Access
- T1528 Steal Application Access Token
- T1550.004 Use Alternate Authentication Material: Web Session Cookie
- T1087 Account Discovery
- T1565.001 Data Manipulation: Stored Data Manipulation
- T1589 Gather Victim Identity Information

## Sources

- [Session Cookie Authentication Bypass: Predictable Signing Secret Enables Account Impersonation (Resecurity)](https://www.resecurity.com/blog/article/session-cookie-authentication-bypass-predictable-signing-secret-enableds-account-impersonations)
- [Session Cookie Vulnerability Lets Attackers Bypass Entra ID MFA and Impersonate Users (Cyber Security News)](https://cybersecuritynews.com/session-cookie-vulnerability/)
- [Authentication Bypass Successfully Impersonated 95 Users Without Passwords or MFA (GBHackers)](https://gbhackers.com/passwordless-impersonation/)
- [Session Cookie Vulnerability Lets Attackers Bypass Entra ID MFA and Impersonate Users (Cryptika)](https://www.cryptika.com/session-cookie-vulnerability-lets-attackers-bypass-entra-id-mfa-and-impersonate-users/)
- [Predictable Session Cookie Secret Enabled Entra MFA Bypass and Account Impersonation (Mallory)](https://mallory.ai/stories/01a0f8e3-f79e-7b61-8aac-7af72115750a)
- [MITRE ATT&CK T1550.004 Use Alternate Authentication Material: Web Session Cookie](https://attack.mitre.org/techniques/T1550/004/)
- [MITRE ATT&CK T1606.001 Forge Web Credentials: Web Cookies](https://attack.mitre.org/techniques/T1606/001/)
- [Cookie-Bite: How Your Digital Crumbs Let Threat Actors Bypass MFA (Varonis, related session-cookie MFA bypass)](https://www.varonis.com/blog/cookie-bite)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-2892
