PT-2026-88439 · Okta · Okta Hyperdrive Agent

CVE-2026-78629

·

Published

2026-09-08

·

Updated

2026-09-08

CVSS v3.1

5.6

Medium

VectorAV:L/AC:H/PR:L/UI:N/S:C/C:N/I:H/A:N
The Okta Hyperdrive agent plugin returns a success response without a signed SAML assertion when the organization's policy requires no MFA for a given user. The response contains only a bare boolean validation indicator with no cryptographic artifact, resulting in an unverifiable authentication verdict being delivered to the relying application.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-78629

Affected Products

Okta Hyperdrive Agent