Search
Search Results (2 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-78629 | 1 Okta | 1 Okta Hyperdrive Agent | 2026-09-13 | 5.6 Medium |
| The Okta Hyperdrive agent plugin returns a success response without a signed SAML assertion when the organization's policy requires no MFA for a given user. The response contains only a bare boolean validation indicator with no cryptographic artifact, resulting in an unverifiable authentication verdict being delivered to the relying application. | ||||
| CVE-2026-78631 | 1 Okta | 1 Okta Hyperdrive Agent | 2026-09-13 | 5.3 Medium |
| The Okta Hyperdrive Agent writes the decoded SAML bearer assertion to a local application log file at the default log level on every successful MFA completion. This insertion of sensitive information into the log file makes a live authentication credential readable by any local user with access to the log file. | ||||
Page 1 of 1.