Improper Validation of SSH Target in Okta Privileged Access Client CVE-2026-77585 - Aug 25, 2026
Description
The Okta Privileged Access client does not reject a leading hyphen in the username portion of an SSH target. As a result, the value may be interpreted as a command-line option by the underlying SSH process.
Affected product and versions
Customers using the Okta Privileged Access client versions 1.59.0 through 1.110.0 are affected.
Customer Recommendations
To remediate this vulnerability, upgrade the Okta Privileged Access client to version 1.111.1 or greater.
Resolution
The vulnerability is present in the Okta Privileged Access client versions 1.59.0 to 1.110.0 and resolved in the Okta Privileged Access client version 1.111.1.
CVE details
CVE ID | |
Published Date | 2026-08-25 |
Vulnerability Type | Arbitrary Command Injection |
CWE | CWE-78 - Improper Neutralization of Special Elements used in an OS Command |
CVSS v3 | Score: 5.3 Vector string: https://www.first.org/cvss/calculator/3-1#CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:L/A:N |