CVE-2026-78627
The Okta Hyperdrive Integration installer does not mask the OAuth client secret when passed as an MSI property. The credential is recorded in plaintext in the installer log, the Application Event Log, and the process command line, all of which are readable by an authenticated local user on the workstation.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.3
- CVSS vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N
- CWE
- CWE-532
- Published
- 2026-09-08
- Last modified
- 2026-09-08
Affected products
- Okta Okta Hyperdrive Integration Plugin
Weakness type
Related vulnerabilities
- CVE-2026-79966 — CWE-532: Insertion of Sensitive Information into Log File
- CVE-2026-80169 — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to...
- CVE-2025-46808 — Sensitive information is leaked into NeuVector’s manager container logs
- CVE-2026-80124 — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to...
- CVE-2026-78631 — Improper Restriction of Sensitive Information in Okta Hyperdrive Agent Logging
- CVE-2026-68873 — Windows Program Compatibility Assistant Service Information Disclosure Vulnerability
- CVE-2026-86597 — Sensitive information written to logs by Snowflake drivers
- CVE-2026-86501 — In JetBrains IntelliJ IDEA before 2026.2.2 terminal command input could be written to idea.log