CVE-2026-78631

The Okta Hyperdrive Agent writes the decoded SAML bearer assertion to a local application log file at the default log level on every successful MFA completion. This insertion of sensitive information into the log file makes a live authentication credential readable by any local user with access to the log file.
Configurations

No configuration.

History

No history.

Information

Published : 2026-09-08 21:18

Updated : 2026-09-10 15:17


NVD link : CVE-2026-78631

Mitre link : CVE-2026-78631

CVE.ORG link : CVE-2026-78631


JSON object : View

Products Affected

No product.

CWE
CWE-532

Insertion of Sensitive Information into Log File