HomepageOkta logo

Improper Authentication Verification in the Okta Hyperdrive Agent MFA Response Handling CVE-2026-78629 - Sep 8, 2026

View all security advisories

Description

The Okta Hyperdrive agent plugin returns a success response without a signed SAML assertion when the organization’s policy requires no MFA for a given user. The response contains only a bare boolean validation indicator with no cryptographic artifact, resulting in an unverifiable authentication verdict being delivered to the relying application.

Affected product and versions

Customers using the Okta Hyperdrive agent versions 1.2.0 through 1.5.1 are affected.

Customer Recommendations

To remediate this vulnerability, upgrade the Okta Hyperdrive agent to version 1.5.2 or greater.

Download version 1.5.2 of the Okta Hyperdrive Integration plugin

Resolution

The vulnerability is present in the Okta Hyperdrive agent versions 1.2.0 through 1.5.1 and is resolved in version 1.5.2.

CVE details

CVE ID

CVE-2026-78629

Published Date

2026-09-08

Vulnerability Type

Improper Authentication

CWE

CWE-303 – Incorrect Implementation of Authentication Algorithm

CVSS v3

Score: 5.6

Vector string: CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:N/I:H/A:N