Aller au contenu

Fiche vulnérabilité

CVE-2026-78627 : faille moyenne okta hyperdrive (CVSS 5.5)

Description

The Okta Hyperdrive Integration installer does not mask the OAuth client secret when passed as an MSI property. The credential is recorded in plaintext in the installer log, the Application Event Log, and the process command line, all of which are readable by an authenticated local user on the workstation.

En bref

Sévérité
Moyenne (CVSS 5.5)
Vecteur CVSS
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Exploitation active
Non signalée par la CISA
Publication
8 sept. 2026
Dernière mise à jour
22 sept. 2026

Produits concernés

  • okta hyperdrive

Références

Rechercher une autre vulnérabilité dans la base CVE