Improper Credential Protection in Okta Hyperdrive Integration Installer Logging CVE-2026-78627 - Sep 8, 2026
Description
The Okta Hyperdrive Integration installer does not mask the OAuth client secret when passed as an MSI property. The credential is recorded in plaintext in the installer log, the Application Event Log, and the process command line, all of which are readable by an authenticated local user on the workstation.
Affected product and versions
Customers using the Okta Hyperdrive Integration plugin versions 1.2.0 through 1.5.1 are affected.
Preconditions
This applies if the following preconditions are present:
The agent was installed with the OAuth client secret passed as an MSI property on the installer command line,
A user has local authenticated access on the Windows host where the agent was installed.
Customer Recommendations
To remediate this vulnerability, upgrade the Okta Hyperdrive Integration plugin to version 1.5.2 or greater.
Download version 1.5.2 of the Okta Hyperdrive Integration plugin
Resolution
The vulnerability is present in the Okta Hyperdrive Integration plugin versions 1.2.0 to 1.5.1 and has been resolved in version 1.5.2.
CVE details
CVE ID | |
Published Date | 2026-09-08 |
Vulnerability Type | Sensitive Data Exposure |
CWE | CWE-532 – Insertion of Sensitive Information into Log File |
CVSS v3 | Score: 7.3 Vector string: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N |