Session Cookie Vulnerability Allows MFA Bypass and User Impersonation in Yard Management Platform
A custom session-cookie system flaw in a yard management platform enabled attackers to bypass Microsoft Entra ID MFA and impersonate users by forging session cookies.

A significant security vulnerability has been identified in a custom session-cookie system used by a yard management platform, allowing unauthenticated attackers to bypass Microsoft Entra ID's multi-factor authentication (MFA) and impersonate legitimate users, including administrators. The flaw, detailed in a report by Resecurity, does not compromise Microsoft Entra ID itself but exploits a weakness in the application's session management layer.
The affected platform integrated with Entra ID for single sign-on and MFA. However, it also relied on a signed cookie to maintain user sessions. The vulnerability stemmed from a hard-coded secret used to sign these session cookies, which attackers could leverage to forge valid session cookies. This allowed them to create authenticated sessions without needing the user's password or MFA approval, effectively bypassing the primary security controls.
Researchers successfully impersonated 95 employee accounts out of 241 tested user IDs, including those with elevated administrative privileges. A forged administrator session enabled the execution of state-changing API requests, posing a substantial risk of operational data exposure and unauthorized actions performed under the guise of a legitimate employee.
The root cause involved two critical design errors: the application signed session cookies using a predictable, hard-coded secret that was the same as the cookie's name, and the signed value contained a user's publicly exposed database identifier (CUID). This CUID could be obtained from various API responses, including an authenticated-user endpoint. With a predictable secret, an attacker could craft a cookie that the server would trust as belonging to another user.
This application-level weakness highlights a common pitfall where strong upstream identity solutions like Entra ID MFA can be undermined by insecure session management practices. The attack vector bypassed the need for Entra ID access tokens or MFA prompts, as the forged cookie alone was sufficient to establish a trusted session. The platform's broader security measures, such as RS256-signed access tokens and schema validation, were sound, but the separate session cookie provided an alternative path for compromise.
Adding to the security concerns, an unauthenticated Swagger interface was also discovered, exposing the platform's complete API surface of 251 routes. This interface provided attackers with valuable information about the API's structure and functionality, potentially aiding in the exploitation of other vulnerabilities.
To mitigate this risk, organizations are advised to immediately rotate the compromised session-signing secret and invalidate all existing sessions. A thorough review of authentication and application logs for suspicious activity, such as unusual session creation or administrative actions, is crucial. Developers should replace predictable, client-controlled session values with randomly generated, server-verified session identifiers and use secure, environment-specific secrets.
The incident serves as a stark reminder that while MFA verifies the initial login event, robust session management is critical for maintaining security throughout a user's interaction with an application. Implementing secure session revocation, monitoring for anomalous behavior, and ensuring that custom application layers do not introduce new attack vectors are essential steps in defending against such sophisticated bypass techniques.