Input Validation Flaw in Okta Privileged Access Client
CVE-2026-78635
5MEDIUM
What is CVE-2026-78635?
A security flaw in the Okta Privileged Access Client arises from the improper handling of command-line arguments within the URL handler for scaleft:// protocol links. If a target value starts with a hyphen, the command-line interface misinterprets it as a flag, potentially altering the intended behavior of the SSH client. This could result in unintended command execution or altered access controls, posing a risk to environment security.
Affected Version(s)
Okta Privileged Access Client 1.18.0 < 1.113.0
