Authentication Bypass Successfully Impersonated 95 Users Without Passwords or MFA

A critical authentication bypass that enabled the impersonation of 95 employee accounts, including privileged users, without passwords, multi-factor authentication (MFA), or valid Microsoft Entra ID tokens. The issue stemmed from two flaws in the application’s custom session-cookie implementation: a predictable hard-coded signing secret and the use of public database identifiers as authenticated session payloads. Although […]

This article has been indexed from GBHackers Security | #1 Globally Trusted Cyber Security News Platform

Read the original article: