CVE-2026-78627
7.3
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N
Summary
The Okta Hyperdrive Integration installer does not mask the OAuth client secret when passed as an MSI property. The credential is recorded in plaintext in the installer log, the Application Event Log, and the process command line, all of which are readable by an authenticated local user on the workstation.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Okta | Okta Hyperdrive Integration Plugin | 1.2.0 < 1.5.2 | affected |
Weaknesses
- CWE-532: Insertion of Sensitive Information into Log File
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.