Session Cookie Authentication Bypass: Predictable Signing Secret Enables Account Impersonations
Resecurity, Thursday, October 1st, 2026
Resecurity found a hard-coded session cookie secret in a yard management system that let testers forge sessions for any user.
During a security review of a supply chain yard management system, Resecurity found two weaknesses in its session-cookie design.
The cookie was signed with a hard-coded secret identical to the cookie name, and it protected the user's public database ID instead of a random session identifier.
Testers obtained user IDs from exposed API responses and recovered the secret through an offline search, then forged sessions for multiple employees, including privileged accounts, bypassing passwords and MFA.