Back Issues/Search Home → Calendar → Archive → RSS → Subscribe → Current Issue → Popular →

All issues › Volume 342, Issue 5 › IT Vendor News › Resecurity

Session Cookie Authentication Bypass: Predictable Signing Secret Enables Account Impersonations

Resecurity, Thursday, October 1st, 2026

Resecurity found a hard-coded session cookie secret in a yard management system that let testers forge sessions for any user.

During a security review of a supply chain yard management system, Resecurity found two weaknesses in its session-cookie design.

The cookie was signed with a hard-coded secret identical to the cookie name, and it protected the user's public database ID instead of a random session identifier.

Testers obtained user IDs from exposed API responses and recovered the secret through an offline search, then forged sessions for multiple employees, including privileged accounts, bypassing passwords and MFA.

more →  ·  More from Resecurity →