CVE-2026-78631 PUBLISHED

Improper Restriction of Sensitive Information in Okta Hyperdrive Agent Logging

Assigner: Okta
Reserved: 24.08.2026 Published: 08.09.2026 Updated: 08.09.2026

The Okta Hyperdrive Agent writes the decoded SAML bearer assertion to a local application log file at the default log level on every successful MFA completion. This insertion of sensitive information into the log file makes a live authentication credential readable by any local user with access to the log file.

Metrics

CVSS Vector: CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:N
CVSS Score: 5.3

Product Status

Vendor Okta
Product Okta Hyperdrive Agent
Versions Default: unaffected
  • affected from 1.4.0 to 1.5.2 (excl.)

Solutions

Upgrade the Okta Hyperdrive Agent to version 1.5.2 or greater.

References

Problem Types

  • Insertion of Sensitive Information into Log File