OktaCVE-2026-78635
Okta Privileged Access Client: argument injection
Medium5.0CVE-2026-78635 · Published Sep 8, 2026 · updated Sep 10, 2026
The Okta Privileged Access client URL handler does not insert an option terminator before appending the target value to the command-line arguments. When a scaleft:// protocol handler link contains a value beginning with a hyphen, the underlying CLI framework interprets it as a command-line flag, causing unintended modification of the SSH client's behavior.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Okta Privileged Access Client Product | >= 1.18.0, < 1.113.0 | 1.113.0 |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-88
More Okta advisories
All Okta| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 8 | Okta Auth0 AD/LDAP Connector: missing authentication | Medium6.7 | No fix yet |
| Sep 8 | Okta Auth0 AD/LDAP Connector: cross-site scripting | Critical9.0 | No fix yet |
| Sep 8 | Okta Auth0 AD/LDAP Connector: code execution | High7.8 | No fix yet |
| Sep 8 | The react-native-auth0 SDK's web platform implementation does not scope its... | Medium6.5 | 5.11.1 |
| Sep 8 | Okta Verify for Windows: link following | Medium6.0 | 7.0.0 |
| Sep 8 | The Okta Hyperdrive agent plugin returns a success response without a signed... | Medium5.6 | 1.5.2 |