Description
The Okta Hyperdrive Integration plugin resolves a required assembly using a registry path within the current user's hive without integrity verification. The referenced path is loaded via Assembly.LoadFrom without signature validation, resulting in an unverified assembly executing within the context of the host process or elevated installer.
Published: 2026-09-08
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The Okta Hyperdrive Integration plugin resolves a required assembly with a registry path that resides in the current user's hive, without performing integrity checks. The referenced path is then loaded via Assembly.LoadFrom, which does not verify the assembly's digital signature. As a result, an untrusted DLL can be executed within the context of the host process or even an elevated installer, allowing arbitrary code execution at the privilege level of the running process. This flaw corresponds to the coalition of untrusted file or resource injection weaknesses and can lead to complete loss of confidentiality, integrity, and availability of the affected system.

Affected Systems

The vulnerability affects the Okta Hyperdrive Integration plugin, as identified by the CNA. No specific version information is included in the provided data, so all current or older installations of this plugin are potentially impacted until the fix is applied.

Risk and Exploitability

The CVSS score of 7.5 indicates a high severity risk, though the EPSS score is not provided, and the issue is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is that an attacker who can influence the registry settings or supply a malicious assembly will trigger the plugin to load the unverified DLL, resulting in remote code execution. The flaw requires that the attacker can provide the DLL and influence the plugin’s registry path resolution—conditions that might be met by compromising the host or modifying the plugin configuration.

Generated by OpenCVE AI on September 9, 2026 at 09:27 UTC.

Remediation

Vendor Solution

Upgrade the Okta Hyperdrive Integration plugin to version 1.5.2 or greater.


OpenCVE Recommended Actions

  • Upgrade the Okta Hyperdrive Integration plugin to version 1.5.2 or later.
  • Restrict access to the registry keys used for assembly resolution, ensuring only trusted administrators can modify them.
  • Monitor the registry for unexpected changes to the plugin’s assembly path and review system logs for abnormal plugin behavior.

Generated by OpenCVE AI on September 9, 2026 at 09:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 23 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
First Time appeared Okta hyperdrive
CPEs cpe:2.3:a:okta:hyperdrive:*:*:*:*:*:*:*:*
Vendors & Products Okta hyperdrive

Sun, 13 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Okta
Okta okta Hyperdrive Integration Plugin
Vendors & Products Okta
Okta okta Hyperdrive Integration Plugin

Thu, 10 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description The Okta Hyperdrive Integration plugin resolves a required assembly using a registry path within the current user's hive without integrity verification. The referenced path is loaded via Assembly.LoadFrom without signature validation, resulting in an unverified assembly executing within the context of the host process or elevated installer.
Title Improper Assembly Resolution in Okta Hyperdrive Integration Plugin Registry Handling
Weaknesses CWE-426
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N'}


Subscriptions

Okta Hyperdrive Okta Hyperdrive Integration Plugin
cve-icon MITRE

Status: PUBLISHED

Assigner: Okta

Published:

Updated: 2026-09-10T14:36:50.101Z

Reserved: 2026-08-24T20:39:00.874Z

Link: CVE-2026-78574

cve-icon Vulnrichment

Updated: 2026-09-10T14:36:44.522Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T20:18:36.417

Modified: 2026-09-23T18:12:49.403

Link: CVE-2026-78574

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-13T20:06:59Z

Weaknesses