HomepageOkta logo

Improper Input Validation in the Okta Privileged Access SSH Client URL Handler Argument CVE-2026-78635 - Sep 8, 2026

View all security advisories

Description

The Okta Privileged Access client URL handler does not insert an option terminator before appending the target value to the command-line arguments. When a scaleft:// protocol handler link contains a value beginning with a hyphen, the underlying CLI framework interprets it as a command-line flag, causing unintended modification of the SSH client's behavior.

Affected product and versions

Customers using the Okta Privileged Access client versions 1.18.0 through 1.112.0 are affected.

Customer Recommendations

To remediate this vulnerability, upgrade the Okta Privileged Access client to version 1.113.0.

Resolution

The vulnerability is present in the Okta Privileged Access client versions 1.18.0 to 1.112.0 and resolved in Okta Privileged Access client version 1.113.0.

CVE details

CVE ID

CVE-2026-78635

Published Date

2026-09-08

Vulnerability Type

Argument Injection

CWE

CWE-88 – Improper Neutralization of Argument Delimiters in a Command

CVSS v3

Score: 5.0

Vector string: CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L

References

Install the Okta Privileged Access client