CVE-2026-77585
Received Received - Intake

Okta Privileged Access Client SSH Username Option Injection

Vulnerability report for CVE-2026-77585, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-25

Last updated on: 2026-08-25

Assigner: Okta

Description

The Okta Privileged Access client does not reject a leading hyphen in the username portion of an SSH target. As a result, the value may be interpreted as a command-line option by the underlying SSH process.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-25
Last Modified
2026-08-25
Generated
2026-08-26
AI Q&A
2026-08-25
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
okta privileged_access_client From 1.59.0 (inc) to 1.110.0 (inc)
okta privileged_access_client 1.111.1
okta privileged_access_client *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-78 The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The Okta Privileged Access client mishandles usernames in SSH targets by not blocking leading hyphens. This allows the username to be treated as a command-line option by the SSH process, potentially enabling unintended command execution or parameter manipulation.

Detection Guidance

Check Okta Privileged Access client logs for SSH connections with usernames starting with a hyphen. Inspect SSH command execution traces for unexpected option flags in usernames. No specific commands are provided in the context.

Impact Analysis

An attacker could exploit this to pass malicious options to SSH, leading to unauthorized access, data exfiltration, or privilege escalation on systems using Okta Privileged Access for SSH connections.

Compliance Impact

This vulnerability could potentially violate compliance requirements under GDPR and HIPAA by enabling unauthorized command execution, which may lead to unauthorized access to sensitive data. Improper validation of SSH target usernames may allow attackers to inject commands, compromising data integrity and confidentiality.

Mitigation Strategies

Update the Okta Privileged Access client to the latest version. Configure SSH clients to reject usernames starting with hyphens. Review and restrict SSH target configurations to prevent command injection.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-77585. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart