Improper Credential Protection in Okta Hyperdrive Integration Installer
CVE-2026-78627

7.3HIGH

Key Information:

Vendor

Okta

Vendor
CVE Published:
8 September 2026

What is CVE-2026-78627?

The Okta Hyperdrive Integration installer has a significant issue where the OAuth client secret is not properly masked when passed as an MSI property. This credential is logged in plaintext in various logs, including the installer log, the Application Event Log, and the process command line. Consequently, any authenticated local user on the workstation can access and read these logs, posing a risk of credential exposure.

Affected Version(s)

Okta Hyperdrive Integration Plugin 1.2.0 < 1.5.2

References

CVSS V3.1

Score:
7.3
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.