Improper Authentication in Okta Hyperdrive Agent Plugin
CVE-2026-78629

5.6MEDIUM

Key Information:

Vendor

Okta

Vendor
CVE Published:
8 September 2026

What is CVE-2026-78629?

The Okta Hyperdrive Agent Plugin contains a vulnerability that allows a success response to be returned without a signed SAML assertion, neglecting organizational policies that require multi-factor authentication (MFA). This leads to the transmission of an unverified authentication result, which can expose applications to unauthorized access. The response only provides a boolean validation indicator, lacking any cryptographic assurances, making it impossible for the relying application to verify the authenticity of the user's identification. This vulnerability underscores the importance of robust authentication mechanisms to ensure security compliance.

Affected Version(s)

Okta Hyperdrive Agent 1.2.0 < 1.5.2

References

CVSS V3.1

Score:
5.6
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.