Skip to content
OktaCVE-2026-77585

Okta Privileged Access Client: command injection

Medium5.3CVE-2026-77585 · Published Aug 25, 2026 · updated Aug 28, 2026

The Okta Privileged Access client does not reject a leading hyphen in the username portion of an SSH target. As a result, the value may be interpreted as a command-line option by the underlying SSH process.

Okta advisory

Affected versions

PackageAffectedFixed in
Okta Privileged Access Client
Product
>= 1.59.0, < 1.111.11.111.1
Details and references

More Okta advisories

All Okta
Advisory
The Okta Access Gateway Kerberos configuration handler does not validate file...
Medium5.9Sep 8
The Okta Access Gateway does not sanitize SAML assertion attribute values...
Medium6.8Sep 8
Okta Hyperdrive Integration Plugin: untrusted search path
High7.5Sep 8
Okta Access Gateway: improper authentication
Medium4.8Sep 8
Okta Access Gateway: code execution
Medium6.6Sep 8
Okta Access Gateway: code injection
Medium6.6Sep 8

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.