Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2765▲ 18 respecto a la semana anterior
Críticas / altas1467▲ 291 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)68▼ 441 respecto a la semana anterior
4 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.5) | 0.14% | — | Okta Hyperdrive | 8/9/2026 | 22/9/2026 | The Okta Hyperdrive Agent writes the decoded SAML bearer assertion to a local application log file at the default log level on every successful MFA completion. This insertion of sensitive information into the log file makes a live authentication credential readable by any local user with access to the log file. | |
| Analizada | Media (5.5) | 0.14% | — | Okta Hyperdrive | 8/9/2026 | 22/9/2026 | The Okta Hyperdrive agent plugin returns a success response without a signed SAML assertion when the organization's policy requires no MFA for a given user. The response contains only a bare boolean validation indicator with no cryptographic artifact, resulting in an unverifiable authentication verdict being delivered… | |
| Analizada | Media (5.5) | 0.14% | — | Okta Hyperdrive | 8/9/2026 | 22/9/2026 | The Okta Hyperdrive Integration installer does not mask the OAuth client secret when passed as an MSI property. The credential is recorded in plaintext in the installer log, the Application Event Log, and the process command line, all of which are readable by an authenticated local user on the workstation. | |
| Analizada | Media (6.3) | 0.10% | — | Okta Hyperdrive | 8/9/2026 | 23/9/2026 | The Okta Hyperdrive Integration plugin resolves a required assembly using a registry path within the current user's hive without integrity verification. The referenced path is loaded via Assembly.LoadFrom without signature validation, resulting in an unverified assembly executing within the context of the host process… |