« Back to list

Okta

Okta Hyperdrive: vulnerabilities and CVEs

Okta Hyperdrive has 4 published vulnerabilities, 4 of them in the last 12 months. 0 are rated critical and 0 are listed by CISA as actively exploited.

CVEs4
Last 12 months4
Critical0
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-78631Medium (5.5)0.14%—Sep 8, 2026
The Okta Hyperdrive Agent writes the decoded SAML bearer assertion to a local application log file at the default log level on every successful MFA completion. This insertion of sensitive information into the log file…
CVE-2026-78629Medium (5.5)0.14%—Sep 8, 2026
The Okta Hyperdrive agent plugin returns a success response without a signed SAML assertion when the organization's policy requires no MFA for a given user. The response contains only a bare boolean validation indicator…
CVE-2026-78627Medium (5.5)0.14%—Sep 8, 2026
The Okta Hyperdrive Integration installer does not mask the OAuth client secret when passed as an MSI property. The credential is recorded in plaintext in the installer log, the Application Event Log, and the process…
CVE-2026-78574Medium (6.3)0.10%—Sep 8, 2026
The Okta Hyperdrive Integration plugin resolves a required assembly using a registry path within the current user's hive without integrity verification. The referenced path is loaded via Assembly.LoadFrom without…

Other products by Okta