HomepageOkta logo

Improper Validation of SSH Target in Okta Privileged Access Client CVE-2026-77585 - Aug 25, 2026

View all security advisories

Description

The Okta Privileged Access client does not reject a leading hyphen in the username portion of an SSH target. As a result, the value may be interpreted as a command-line option by the underlying SSH process.

Affected product and versions

Customers using the Okta Privileged Access client versions 1.59.0 through 1.110.0 are affected.

Customer Recommendations

To remediate this vulnerability, upgrade the Okta Privileged Access client to version 1.111.1 or greater.

Resolution

The vulnerability is present in the Okta Privileged Access client versions 1.59.0 to 1.110.0 and resolved in the Okta Privileged Access client version 1.111.1.

CVE details

CVE ID

CVE-2026-77585

Published Date

2026-08-25

Vulnerability Type

Arbitrary Command Injection

CWE

CWE-78 - Improper Neutralization of Special Elements used in an OS Command

CVSS v3

Score: 5.3

Vector string: https://www.first.org/cvss/calculator/3-1#CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:L/A:N