PT-2026-88438 · Okta · Okta Hyperdrive Integration Plugin

CVE-2026-78627

·

Published

2026-09-08

·

Updated

2026-09-08

CVSS v3.1

7.3

High

VectorAV:L/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N
The Okta Hyperdrive Integration installer does not mask the OAuth client secret when passed as an MSI property. The credential is recorded in plaintext in the installer log, the Application Event Log, and the process command line, all of which are readable by an authenticated local user on the workstation.

Fix

Insertion into Log File

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-78627

Affected Products

Okta Hyperdrive Integration Plugin