Improper Information Disclosure in Okta Hyperdrive Agent Logging
CVE-2026-78631

5.3MEDIUM

Key Information:

Vendor

Okta

Vendor
CVE Published:
8 September 2026

What is CVE-2026-78631?

The Okta Hyperdrive Agent is susceptible to a vulnerability that causes the sensitive SAML bearer assertion to be logged in a local application log file during successful Multi-Factor Authentication (MFA) completions. This exposure allows any local user with access to the log file to potentially read these sensitive authentication credentials, which could lead to unauthorized access. It is crucial for users and administrators to ensure that logs are properly secured and monitored to mitigate the risks associated with this vulnerability.

Affected Version(s)

Okta Hyperdrive Agent 1.4.0 < 1.5.2

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.