Improper Authentication in Okta Hyperdrive Agent Plugin
CVE-2026-78629
5.6MEDIUM
What is CVE-2026-78629?
The Okta Hyperdrive Agent Plugin contains a vulnerability that allows a success response to be returned without a signed SAML assertion, neglecting organizational policies that require multi-factor authentication (MFA). This leads to the transmission of an unverified authentication result, which can expose applications to unauthorized access. The response only provides a boolean validation indicator, lacking any cryptographic assurances, making it impossible for the relying application to verify the authenticity of the user's identification. This vulnerability underscores the importance of robust authentication mechanisms to ensure security compliance.
Affected Version(s)
Okta Hyperdrive Agent 1.2.0 < 1.5.2
