Executive brief
The StrongDM desktop application for Windows was found to store sensitive login information, including security tokens and encryption keys, in plain text on the user's computer. If an unauthorized person or malicious software gains access to the user's local files, they could potentially steal these credentials to impersonate the user and access corporate infrastructure. This issue has been addressed in newer versions of the software.
Technical details
The StrongDM Desktop Application (before 23.74.0) and Desktop Client (before 53.77.0) on Windows store sensitive authentication material in cleartext within the 'state.kv' file located in the user's profile directory. This file contains JSON Web Tokens (JWT) and asymmetric key material protected only by default NTFS user-level permissions. An attacker with local read access to the victim's profile directory could extract these credentials to gain unauthorized access to the StrongDM platform. The vulnerability is classified under CWE-312 (Cleartext Storage of Sensitive Information) and CWE-522 (Insufficiently Protected Credentials).
Affected products
- StrongDM Desktop Application before 23.74.0
- StrongDM Desktop Client before 53.77.0
Timeline
- 2026-05-29: advisory: NVD publication date
- 2026-05-29: disclosed: Coordinated disclosure by SpecterOps