SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-78627

HIGH · CVSS 7.3 EPSS 0.10%

Source: NVD + CISA KEV + EPSS · Published 2026-09-08 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The Okta Hyperdrive Integration installer exposes the OAuth client secret in plaintext through its MSI properties, logging it in the installer log, Application Event Log, and process command line. This vulnerability allows authenticated local users to access sensitive credentials, potentially leading to unauthorized access or data breaches. Organizations using this integration should prioritize remediation to protect their systems from potential exploitation.

CVE
CVE-2026-78627
Severity
HIGH
CVSS
7.3
EPSS
0.10%

Original NVD Description

The Okta Hyperdrive Integration installer does not mask the OAuth client secret when passed as an MSI property. The credential is recorded in plaintext in the installer log, the Application Event Log, and the process command line, all of which are readable by an authenticated local user on the workstation.