PT-2026-88438 · Okta · Okta Hyperdrive Integration Plugin

CVE-2026-78627

·

Publicado

2026-09-08

·

Atualizado

2026-09-08

CVSS v3.1

7.3

Alta

VetorAV:L/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N
The Okta Hyperdrive Integration installer does not mask the OAuth client secret when passed as an MSI property. The credential is recorded in plaintext in the installer log, the Application Event Log, and the process command line, all of which are readable by an authenticated local user on the workstation.

Correção

Insertion into Log File

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-78627

Produtos afetados

Okta Hyperdrive Integration Plugin