Description
The Okta Hyperdrive Integration installer does not mask the OAuth client secret when passed as an MSI property. The credential is recorded in plaintext in the installer log, the Application Event Log, and the process command line, all of which are readable by an authenticated local user on the workstation.
Published: 2026-09-08
Score: 7.3 High
EPSS: < 1% Very Low
KEV: No
Impact: Credential Exposure through Installer Logging
Action: Apply Patch
AI Analysis

Impact

The Okta Hyperdrive Integration installer records the OAuth client secret in clear text when the secret is passed as an MSI property. The plaintext credential is written to the installer log, the Application Event Log, and the process command line, all of which can be accessed by any authenticated local user on the workstation. The vulnerability allows a local user to obtain an OAuth client secret that can be used to impersonate or compromise the Okta integration, leading to potential unauthorized access to integrated applications. The weakness is a failure to mask sensitive data during logging (CWE‑532).

Affected Systems

Any system running the Okta Hyperdrive Integration Plugin prior to version 1.5.2 is impacted. The vendor recommends upgrading to version 1.5.2 or later to mitigate the risk. Exact affected versions prior to the fix are not enumerated in the advisory.

Risk and Exploitability

The advisory lists a CVSS score of 7.3, indicating high risk to confidentiality. The EPSS score is not available; the risk assessment relies on the CVSS severity. The vulnerability is not part of the CISA KEV catalog, but the attack vector is local and requires an authenticated user with standard workstation access. Therefore, any local user with privilege to run installs or view logs could exploit this flaw. The potential impact includes exposure of OAuth credentials that can lead to unauthorized access to linked services.

Generated by OpenCVE AI on September 9, 2026 at 10:24 UTC.

Remediation

Vendor Solution

Upgrade the Okta Hyperdrive Integration plugin to version 1.5.2 or greater.


OpenCVE Recommended Actions

  • Install or update the Okta Hyperdrive Integration Plugin to version 1.5.2 or later to prevent the secret from being logged.
  • If an immediate update is not possible, restrict access to the installer logs and the Application Event Log to administrator accounts only and audit local privilege accounts to ensure only authorized users can run installations.
  • Avoid passing the OAuth client secret as a plain MSI property; instead use secure configuration methods such as encrypted files or environment variables and verify that the installation process does not log sensitive data.

Generated by OpenCVE AI on September 9, 2026 at 10:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 22 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Okta hyperdrive
CPEs cpe:2.3:a:okta:hyperdrive:*:*:*:*:*:*:*:*
Vendors & Products Okta hyperdrive

Sun, 13 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Okta
Okta okta Hyperdrive Integration Plugin
Vendors & Products Okta
Okta okta Hyperdrive Integration Plugin

Thu, 10 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description The Okta Hyperdrive Integration installer does not mask the OAuth client secret when passed as an MSI property. The credential is recorded in plaintext in the installer log, the Application Event Log, and the process command line, all of which are readable by an authenticated local user on the workstation.
Title Improper Credential Protection in Okta Hyperdrive Integration Installer Logging
Weaknesses CWE-532
References
Metrics cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N'}


Subscriptions

Okta Hyperdrive Okta Hyperdrive Integration Plugin
cve-icon MITRE

Status: PUBLISHED

Assigner: Okta

Published:

Updated: 2026-09-10T14:37:14.625Z

Reserved: 2026-08-24T22:04:00.475Z

Link: CVE-2026-78627

cve-icon Vulnrichment

Updated: 2026-09-10T14:37:10.258Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T20:18:38.440

Modified: 2026-09-22T20:10:34.717

Link: CVE-2026-78627

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-13T20:06:56Z

Weaknesses
  • CWE-532

    Insertion of Sensitive Information into Log File