Improper Credential Protection in Okta Hyperdrive Integration Installer
CVE-2026-78627
7.3HIGH
What is CVE-2026-78627?
The Okta Hyperdrive Integration installer has a significant issue where the OAuth client secret is not properly masked when passed as an MSI property. This credential is logged in plaintext in various logs, including the installer log, the Application Event Log, and the process command line. Consequently, any authenticated local user on the workstation can access and read these logs, posing a risk of credential exposure.
Affected Version(s)
Okta Hyperdrive Integration Plugin 1.2.0 < 1.5.2
