Skip to content
OktaCVE-2026-78629

The Okta Hyperdrive agent plugin returns a success response without a signed...

Medium5.6CVE-2026-78629 · Published Sep 8, 2026 · updated Sep 22, 2026

The Okta Hyperdrive agent plugin returns a success response without a signed SAML assertion when the organization's policy requires no MFA for a given user. The response contains only a bare boolean validation indicator with no cryptographic artifact, resulting in an unverifiable authentication verdict being delivered to the relying application.

Okta advisory

Affected versions

PackageAffectedFixed in
Okta Hyperdrive Agent
Product
>= 1.2.0, < 1.5.21.5.2
Details and references

More Okta advisories

All Okta
Advisory
Okta Auth0 AD/LDAP Connector: missing authentication
Medium6.7Sep 8
Okta Auth0 AD/LDAP Connector: cross-site scripting
Critical9.0Sep 8
Okta Auth0 AD/LDAP Connector: code execution
High7.8Sep 8
The react-native-auth0 SDK's web platform implementation does not scope its...
Medium6.5Sep 8
Okta Verify for Windows: link following
Medium6.0Sep 8
Okta Access Gateway: command injection
Medium6.7Sep 8

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.