Input Validation Flaw in Okta Privileged Access Client
CVE-2026-78635

5MEDIUM

Key Information:

Vendor

Okta

Vendor
CVE Published:
8 September 2026

What is CVE-2026-78635?

A security flaw in the Okta Privileged Access Client arises from the improper handling of command-line arguments within the URL handler for scaleft:// protocol links. If a target value starts with a hyphen, the command-line interface misinterprets it as a flag, potentially altering the intended behavior of the SSH client. This could result in unintended command execution or altered access controls, posing a risk to environment security.

Affected Version(s)

Okta Privileged Access Client 1.18.0 < 1.113.0

References

CVSS V3.1

Score:
5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.