5.5

CVE-2026-78629

Improper Authentication Verification in the Okta Hyperdrive Agent MFA Response Handling

The Okta Hyperdrive agent plugin returns a success response without a signed SAML assertion when the organization's policy requires no MFA for a given user. The response contains only a bare boolean validation indicator with no cryptographic artifact, resulting in an unverifiable authentication verdict being delivered to the relying application.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Okta ≫ Hyperdrive Version >= 1.2.0 < 1.5.2
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.1% 0.009
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.5 1.8 3.6
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
psirt@okta.com 5.6 1.1 4
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:N/I:H/A:N
CWE-303 Incorrect Implementation of Authentication Algorithm

The requirements for the product dictate the use of an established authentication algorithm, but the implementation of the algorithm is incorrect.

https://trust.okta.com/security-advisories/improper-authentication-verification-in-the-okta-hyperdrive-agent-mfa-response-handling-cve-2026-78629
Vendor Advisory