CVE-2026-78574 PUBLISHED

Improper Assembly Resolution in Okta Hyperdrive Integration Plugin Registry Handling

Assigner: Okta
Reserved: 24.08.2026 Published: 08.09.2026 Updated: 08.09.2026

The Okta Hyperdrive Integration plugin resolves a required assembly using a registry path within the current user's hive without integrity verification. The referenced path is loaded via Assembly.LoadFrom without signature validation, resulting in an unverified assembly executing within the context of the host process or elevated installer.

Metrics

CVSS Vector: CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N
CVSS Score: 7.5

Product Status

Vendor Okta
Product Okta Hyperdrive Integration Plugin
Versions Default: unaffected
  • affected from 1.2.0 to 1.5.2 (excl.)

Solutions

Upgrade the Okta Hyperdrive Integration plugin to version 1.5.2 or greater.

References

Problem Types

  • Untrusted Search Path