The Okta Privileged Access client does not reject a leading hyphen in the username portion of an SSH target. As a result, the value may be interpreted as a command-line option by the underlying SSH process.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
Upgrade the Okta Privileged Access client to version 1.111.1 or greater.
Workaround
No workaround given by the vendor.
References
History
Tue, 25 Aug 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Okta Privileged Access client does not reject a leading hyphen in the username portion of an SSH target. As a result, the value may be interpreted as a command-line option by the underlying SSH process. | |
| Title | Improper Validation of SSH Target in Okta Privileged Access Client | |
| Weaknesses | CWE-78 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Okta
Published:
Updated: 2026-08-25T20:09:45.290Z
Reserved: 2026-08-20T20:46:14.393Z
Link: CVE-2026-77585
No data.
Status : Received
Published: 2026-08-25T20:17:06.477
Modified: 2026-08-25T20:17:06.477
Link: CVE-2026-77585
No data.
OpenCVE Enrichment
No data.
Weaknesses