HomepageOkta logo

Improper Credential Protection in Okta Hyperdrive Integration Installer Logging CVE-2026-78627 - Sep 8, 2026

View all security advisories

Description

The Okta Hyperdrive Integration installer does not mask the OAuth client secret when passed as an MSI property. The credential is recorded in plaintext in the installer log, the Application Event Log, and the process command line, all of which are readable by an authenticated local user on the workstation.

Affected product and versions

Customers using the Okta Hyperdrive Integration plugin versions 1.2.0 through 1.5.1 are affected.

Preconditions

This applies if the following preconditions are present:

  • The agent was installed with the OAuth client secret passed as an MSI property on the installer command line,

  • A user has local authenticated access on the Windows host where the agent was installed.

Customer Recommendations

To remediate this vulnerability, upgrade the Okta Hyperdrive Integration plugin to version 1.5.2 or greater.

Download version 1.5.2 of the Okta Hyperdrive Integration plugin

Resolution

The vulnerability is present in the Okta Hyperdrive Integration plugin versions 1.2.0 to 1.5.1 and has been resolved in version 1.5.2.

CVE details

CVE ID

CVE-2026-78627

Published Date

2026-09-08

Vulnerability Type

Sensitive Data Exposure

CWE

CWE-532 – Insertion of Sensitive Information into Log File

CVSS v3

Score: 7.3

Vector string: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N