Metrics
Affected Vendors & Products
No advisories yet.
Solution
Upgrade the Okta Hyperdrive agent to version 1.5.2 or greater.
Workaround
No workaround given by the vendor.
Thu, 10 Sep 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 08 Sep 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Okta Hyperdrive agent plugin returns a success response without a signed SAML assertion when the organization's policy requires no MFA for a given user. The response contains only a bare boolean validation indicator with no cryptographic artifact, resulting in an unverifiable authentication verdict being delivered to the relying application. | |
| Title | Improper Authentication Verification in the Okta Hyperdrive Agent MFA Response Handling | |
| Weaknesses | CWE-303 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Okta
Published:
Updated: 2026-09-10T14:39:42.613Z
Reserved: 2026-08-24T22:04:00.475Z
Link: CVE-2026-78629
Updated: 2026-09-10T14:39:37.874Z
Status : Undergoing Analysis
Published: 2026-09-08T21:18:41.347
Modified: 2026-09-10T15:17:42.413
Link: CVE-2026-78629
No data.
OpenCVE Enrichment
Updated: 2026-09-09T10:30:09Z