CVE-2026-78574
7.5
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N
Summary
The Okta Hyperdrive Integration plugin resolves a required assembly using a registry path within the current user's hive without integrity verification. The referenced path is loaded via Assembly.LoadFrom without signature validation, resulting in an unverified assembly executing within the context of the host process or elevated installer.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Okta | Okta Hyperdrive Integration Plugin | 1.2.0 < 1.5.2 | affected |
Weaknesses
- CWE-426: Untrusted Search Path
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.