CVE-2026-78574
Analyzed Analyzed - Analysis Complete

Okta Hyperdrive Integration Plugin Unverified Assembly Loading

Vulnerability report for CVE-2026-78574, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-08

Last updated on: 2026-09-23

Assigner: Okta

Description

The Okta Hyperdrive Integration plugin resolves a required assembly using a registry path within the current user's hive without integrity verification. The referenced path is loaded via Assembly.LoadFrom without signature validation, resulting in an unverified assembly executing within the context of the host process or elevated installer.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-08
Last Modified
2026-09-23
Generated
2026-09-29
AI Q&A
2026-09-10
EPSS Evaluated
2026-09-27
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
okta hyperdrive From 1.2.0 (inc) to 1.5.1 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-426 The product searches for critical resources using an externally-supplied search path that can point to resources that are not under the product's direct control.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves the Okta Hyperdrive Integration plugin loading an assembly from a registry path in the user's hive without verifying its integrity. The assembly is loaded using Assembly.LoadFrom without signature validation, allowing an unverified assembly to execute within the host process or elevated installer.

Impact Analysis

An attacker could exploit this to execute malicious code in the context of the host process or installer, potentially gaining elevated privileges or compromising sensitive data. The impact includes unauthorized code execution and potential system compromise.

Compliance Impact

This vulnerability could lead to unauthorized access or data breaches, violating compliance requirements such as GDPR (data protection) or HIPAA (health information security). Organizations may face legal penalties or reputational damage due to non-compliance.

Mitigation Strategies

Update or remove the Okta Hyperdrive Integration plugin to ensure assemblies are loaded with integrity verification. Restrict user permissions to prevent unauthorized registry modifications. Monitor system logs for unexpected assembly loads.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-78574. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart