PT-2026-88442 · Okta · Okta Privileged Access Client

CVE-2026-78635

·

Publicado

2026-09-08

·

Atualizado

2026-09-08

CVSS v3.1

5.0

Média

VetorAV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L
The Okta Privileged Access client URL handler does not insert an option terminator before appending the target value to the command-line arguments. When a scaleft:// protocol handler link contains a value beginning with a hyphen, the underlying CLI framework interprets it as a command-line flag, causing unintended modification of the SSH client's behavior.

Correção

Argument Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-78635

Produtos afetados

Okta Privileged Access Client