The Okta Hyperdrive Agent writes the decoded SAML bearer assertion to a local application log file at the default log level on every successful MFA completion. This insertion of sensitive information into the log file makes a live authentication credential readable by any local user with access to the log file.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-09-08 21:18
Updated : 2026-09-10 15:17
NVD link : CVE-2026-78631
Mitre link : CVE-2026-78631
CVE.ORG link : CVE-2026-78631
JSON object : View
Products Affected
No product.
CWE
CWE-532
Insertion of Sensitive Information into Log File
