CVE-2026-78631

Summary

The Okta Hyperdrive Agent writes the decoded SAML bearer assertion to a local application log file at the default log level on every successful MFA completion. This insertion of sensitive information into the log file makes a live authentication credential readable by any local user with access to the log file.

Affected Software

VendorProductVersion RangeStatus
OktaOkta Hyperdrive Agent1.4.0 < 1.5.2affected

Weaknesses

  • CWE-532: Insertion of Sensitive Information into Log File

References