CVE-2026-78631
Analyzed Analyzed - Analysis Complete

Okta Hyperdrive Agent Logs SAML Bearer Assertion

Vulnerability report for CVE-2026-78631, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-08

Last updated on: 2026-09-22

Assigner: Okta

Description

The Okta Hyperdrive Agent writes the decoded SAML bearer assertion to a local application log file at the default log level on every successful MFA completion. This insertion of sensitive information into the log file makes a live authentication credential readable by any local user with access to the log file.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-08
Last Modified
2026-09-22
Generated
2026-09-29
AI Q&A
2026-09-09
EPSS Evaluated
2026-09-27
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
okta hyperdrive From 1.4.0 (inc) to 1.5.2 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-532 The product writes sensitive information to a log file.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The Okta Hyperdrive Agent logs the decoded SAML bearer assertion, including sensitive authentication credentials, to a local application log file after every successful MFA completion. This exposes credentials to any local user with access to the log file.

Detection Guidance

Check Okta Hyperdrive Agent log files for entries containing SAML bearer assertions or authentication credentials. Look for files in default log directories like /var/log/okta/ or application-specific logs. Search for patterns like 'SAML assertion' or 'bearer token' in logs.

Impact Analysis

This vulnerability allows any local user with log file access to read live authentication credentials, leading to potential unauthorized account access or data breaches.

Compliance Impact

This vulnerability likely violates compliance requirements for protecting sensitive authentication data, as it exposes credentials in log files, which could lead to unauthorized access and data breaches.

Mitigation Strategies

Upgrade the Okta Hyperdrive Agent to version 1.5.2 or later immediately. Review and restrict access permissions to log files containing sensitive data. Monitor logs for unauthorized access or exposure of credentials.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-78631. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart