Impact
The Okta Privileged Access Client fails to reject a leading hyphen in the username portion of an SSH target. As a result the hyphenated value can be interpreted as a command‑line option by the underlying SSH process, allowing an attacker to influence the options passed to SSH. This flaw is categorized as CWE‑78 and may enable manipulation of SSH behavior, potentially leading to unintended execution or privilege escalation. (Based on the description, it is inferred that the injected option could change the SSH session).
Affected Systems
All installations of the Okta Privileged Access Client with a version earlier than 1.111.1 are vulnerable. The issue arises whenever the client is used to initiate SSH connections, regardless of the host operating system.
Risk and Exploitability
The CVSS score of 5.3 indicates a medium severity. Because no EPSS score is available, the probability of widespread exploitation is unknown. The vulnerability is not listed in the CISA KEV catalog. The likely attack surface involves an attacker who can specify the SSH target used by the client, such as a user with access to the client’s configuration or a local attacker. (Based on the description, it is inferred that the attacker could provide a crafted target). While the flaw does not provide direct remote code execution, it permits manipulation of SSH command‑line options which could be leveraged to gain unauthorized privilege or bypass restrictions depending on the target environment.
OpenCVE Enrichment