CVE-2026-78629
The Okta Hyperdrive agent plugin returns a success response without a signed SAML assertion when the organization's policy requires no MFA for a given user. The response contains only a bare boolean validation indicator with no cryptographic artifact, resulting in an unverifiable authentication verdict being delivered to the relying application.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 5.6
- CVSS vector
- CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:N/I:H/A:N
- CWE
- CWE-303
- Published
- 2026-09-08
- Last modified
- 2026-09-08
Affected products
- Okta Okta Hyperdrive Agent
Weakness type
Related vulnerabilities
- CVE-2026-9854 — A vulnerability exists in SYS600 RBAC mechanism where users having access to the engineering tools...
- CVE-2026-9853 — A vulnerability exists in SYS600 which allows any user authenticated to the operating system of the...
- CVE-2026-49467 — TOTP enrollment hijack: password gate skipped due to unawaited promise
- CVE-2026-66411 — DEEBOT PRO M1 and DEEBOT PRO K1VAC incorrectly implement authentication algorithm in Websocket...
- CVE-2026-11430 — Grav CMS Scheduler Webhook Authentication Bypass via Null Short-Circuit
- CVE-2026-10050 — Digest authentication lossy encoding
- CVE-2026-59309 — vCenter authentication-bypass vulnerability
- CVE-2026-66028 — Ekushey Project Manager CRM 5.0 Missing Uniqueness Constraint via Client Email