CVE-2026-78627 PUBLISHED

Improper Credential Protection in Okta Hyperdrive Integration Installer Logging

Assigner: Okta
Reserved: 24.08.2026 Published: 08.09.2026 Updated: 08.09.2026

The Okta Hyperdrive Integration installer does not mask the OAuth client secret when passed as an MSI property. The credential is recorded in plaintext in the installer log, the Application Event Log, and the process command line, all of which are readable by an authenticated local user on the workstation.

Metrics

CVSS Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N
CVSS Score: 7.3

Product Status

Vendor Okta
Product Okta Hyperdrive Integration Plugin
Versions Default: unaffected
  • affected from 1.2.0 to 1.5.2 (excl.)

Solutions

Upgrade the Okta Hyperdrive Integration plugin to version 1.5.2 or greater.

References

Problem Types

  • Insertion of Sensitive Information into Log File