A critical authentication bypass that enabled the impersonation of 95 employee accounts, including privileged users, without passwords, multi-factor authentication (MFA), or valid Microsoft Entra ID tokens. The issue stemmed from two flaws in the application’s custom session-cookie implementation: a predictable hard-coded signing secret and the use of public database identifiers as authenticated session payloads. Although […] The post Authentication Bypass Successfully Impersonated 95 Users Without Passwords or MFA appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
First seen on gbhackers.com
Jump to article: gbhackers.com/passwordless-impersonation/
![]()

