Compliance Node Overview
MITRE CAPEC-21 (Exploitation of Trusted Identifiers) is an attack pattern in which an adversary manipulates trusted identifiers (session IDs, cookies, access tokens, SAML assertions, OAuth tokens) to impersonate authenticated users. Prerequisites: weak identifier proof/verification schemes, long-lifetime reusable identifiers, concurrent sessions allowed. Likelihood: High. Severity: High. Maps to MITRE ATT&CK T1134 (Access Token Manipulation), T1528 (Steal Application Access Token), T1539 (Steal Web Session Cookie). CWE-290, CWE-302, CWE-384, CWE-539. Compliance: OWASP ASVS V3, PCI DSS, NIS2.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://capec.mitre.org/data/definitions/21.html
SHA-256 integrity: 6abfc4bfafdcf92c7394b0986a85f91d1d0c92689c63dcf6f2630970017ea224
Primary Citations — 8 traced to source
- MITRE CAPEC-21: Exploitation of Trusted Identifiers (https://capec.mitre.org/data/definitions/21.html)
- CWE-290: Authentication Bypass by Spoofing
+ 6 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access