SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-77585

MEDIUM · CVSS 5.3 EPSS 0.10%

Source: NVD + CISA KEV + EPSS · Published 2026-08-25 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

The Okta Privileged Access client is vulnerable due to its failure to properly handle leading hyphens in the username field of SSH targets, which can lead to the username being misinterpreted as a command-line option by the SSH process. This flaw could potentially allow an attacker to execute arbitrary commands or gain unauthorized access. Organizations using this client should prioritize remediation to mitigate the risk of exploitation.

CVE
CVE-2026-77585
Severity
MEDIUM
CVSS
5.3
EPSS
0.10%

Original NVD Description

The Okta Privileged Access client does not reject a leading hyphen in the username portion of an SSH target. As a result, the value may be interpreted as a command-line option by the underlying SSH process.