Improper Input Validation in the Okta Privileged Access SSH Client URL Handler Argument CVE-2026-78635 - Sep 8, 2026
Description
The Okta Privileged Access client URL handler does not insert an option terminator before appending the target value to the command-line arguments. When a scaleft:// protocol handler link contains a value beginning with a hyphen, the underlying CLI framework interprets it as a command-line flag, causing unintended modification of the SSH client's behavior.
Affected product and versions
Customers using the Okta Privileged Access client versions 1.18.0 through 1.112.0 are affected.
Customer Recommendations
To remediate this vulnerability, upgrade the Okta Privileged Access client to version 1.113.0.
Resolution
The vulnerability is present in the Okta Privileged Access client versions 1.18.0 to 1.112.0 and resolved in Okta Privileged Access client version 1.113.0.
CVE details
CVE ID | |
Published Date | 2026-09-08 |
Vulnerability Type | Argument Injection |
CWE | CWE-88 – Improper Neutralization of Argument Delimiters in a Command |
CVSS v3 | Score: 5.0 Vector string: CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L |