Improper Information Disclosure in Okta Hyperdrive Agent Logging
CVE-2026-78631
5.3MEDIUM
What is CVE-2026-78631?
The Okta Hyperdrive Agent is susceptible to a vulnerability that causes the sensitive SAML bearer assertion to be logged in a local application log file during successful Multi-Factor Authentication (MFA) completions. This exposure allows any local user with access to the log file to potentially read these sensitive authentication credentials, which could lead to unauthorized access. It is crucial for users and administrators to ensure that logs are properly secured and monitored to mitigate the risks associated with this vulnerability.
Affected Version(s)
Okta Hyperdrive Agent 1.4.0 < 1.5.2
