SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-78631

MEDIUM · CVSS 5.3 EPSS 0.10%

Source: NVD + CISA KEV + EPSS · Published 2026-09-08 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The Okta Hyperdrive Agent is vulnerable due to the logging of decoded SAML bearer assertions in a local application log file after successful multi-factor authentication (MFA) completions. This exposure allows any local user with access to the log file to read sensitive authentication credentials, potentially leading to unauthorized access. Organizations using the Okta Hyperdrive Agent should prioritize remediation to mitigate the risk of credential theft.

CVE
CVE-2026-78631
Severity
MEDIUM
CVSS
5.3
EPSS
0.10%

Original NVD Description

The Okta Hyperdrive Agent writes the decoded SAML bearer assertion to a local application log file at the default log level on every successful MFA completion. This insertion of sensitive information into the log file makes a live authentication credential readable by any local user with access to the log file.