Session Cookie Vulnerability Lets Attackers Bypass Entra ID MFA and Impersonate Users
02/10/2026-14:24 02/10/2026-14:25 מחשבים וטכנולוגיה Cyber Security News דיווח
A flaw in a custom session-cookie system allowed an unauthenticated attacker to pose as employees and administrators in a yard management platform. The issue did not break Microsoft Entra ID itself. Instead, it let a weak application-side session lay