CVE-2026-78631
The Okta Hyperdrive Agent writes the decoded SAML bearer assertion to a local application log file at the default log level on every successful MFA completion. This insertion of sensitive information into the log file makes a live authentication credential readable by any local user with access to the log file.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 5.3
- CVSS vector
- CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:N
- CWE
- CWE-532
- Published
- 2026-09-08
- Last modified
- 2026-09-08
Affected products
- Okta Okta Hyperdrive Agent
Weakness type
Related vulnerabilities
- CVE-2026-79966 — CWE-532: Insertion of Sensitive Information into Log File
- CVE-2026-80169 — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to...
- CVE-2025-46808 — Sensitive information is leaked into NeuVector’s manager container logs
- CVE-2026-80124 — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to...
- CVE-2026-78627 — Improper Credential Protection in Okta Hyperdrive Integration Installer Logging
- CVE-2026-68873 — Windows Program Compatibility Assistant Service Information Disclosure Vulnerability
- CVE-2026-86597 — Sensitive information written to logs by Snowflake drivers
- CVE-2026-86501 — In JetBrains IntelliJ IDEA before 2026.2.2 terminal command input could be written to idea.log