URL has been copied successfully!
Authentication Bypass Successfully Impersonated 95 Users Without Passwords or MFA
URL has been copied successfully!

Collecting Cyber-News from over 60 sources

Authentication Bypass Successfully Impersonated 95 Users Without Passwords or MFA

A critical authentication bypass that enabled the impersonation of 95 employee accounts, including privileged users, without passwords, multi-factor authentication (MFA), or valid Microsoft Entra ID tokens. The issue stemmed from two flaws in the application’s custom session-cookie implementation: a predictable hard-coded signing secret and the use of public database identifiers as authenticated session payloads. Although […] The post Authentication Bypass Successfully Impersonated 95 Users Without Passwords or MFA appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

First seen on gbhackers.com

Jump to article: gbhackers.com/passwordless-impersonation/

Loading

Share via Email
Share on Facebook
Tweet on X (Twitter)
Share on Whatsapp
Share on LinkedIn
Share on Xing
Copy link