Improper Input Validation in Okta Privileged Access Client
CVE-2026-77585

5.3MEDIUM

Key Information:

Vendor

Okta

Vendor
CVE Published:
25 August 2026

What is CVE-2026-77585?

The Okta Privileged Access client fails to properly validate the username field in the SSH target input. Specifically, leading hyphens are not adequately rejected, which may allow for unintended command-line option interpretations by the SSH process. This flaw can create security risks by enabling unauthorized command executions. It is crucial for users to ensure that input is sanitized to avoid exploitation through this weakness.

Affected Version(s)

Okta Privileged Access Client 1.59.0 < 1.111.1

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.