Description
The Okta Hyperdrive agent plugin returns a success response without a signed SAML assertion when the organization's policy requires no MFA for a given user. The response contains only a bare boolean validation indicator with no cryptographic artifact, resulting in an unverifiable authentication verdict being delivered to the relying application.
Published: 2026-09-08
Score: 5.6 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Authentication Bypass
Action: Upgrade Agent
AI Analysis

Impact

The vulnerability lies in the Okta Hyperdrive agent’s MFA response handling. When the organization’s policy allows users without MFA, the agent returns a success response that only contains a plain boolean flag, omitting the signed SAML assertion required for credential verification. Consequently, the relying application receives an authentication verdict that cannot be cryptographically validated, which effectively permits authentication without the intended security checks.

Affected Systems

This issue affects the Okta Hyperdrive Agent plugin used within enterprises that rely on Okta for single sign‑on. The affected component is the Okta Hyperdrive Agent, version prior to 1.5.2. Organizations deploying any version earlier than the fixed release are potentially impacted.

Risk and Exploitability

The CVSS score of 5.6 indicates a moderate impact; the vulnerability is not currently present in the CISA KEV catalog and no EPSS data is available, implying a low to moderate likelihood of exploitation. Attackers would need access to a user session where MFA is not required; if they can trigger the response, they may obtain an authentication token that the relying application accepts as valid. Because the flaw arises from missing cryptographic verification, the risk stems from the application trusting unsigned responses rather than the upstream service.

Generated by OpenCVE AI on September 9, 2026 at 10:23 UTC.

Remediation

Vendor Solution

Upgrade the Okta Hyperdrive agent to version 1.5.2 or greater.


OpenCVE Recommended Actions

  • Apply the vendor‑recommended upgrade to Okta Hyperdrive Agent 1.5.2 or later to ensure signed SAML assertions are returned even for non‑MFA users.
  • Enforce cryptographic verification of SAML assertions in the relying application, preventing acceptance of unsigned or unverifiable responses (addresses CWE‑303).
  • Enable detailed authentication logging and set alerts for unsigned SAML responses to detect potential bypass attempts.

Generated by OpenCVE AI on September 9, 2026 at 10:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 22 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
First Time appeared Okta hyperdrive
CPEs cpe:2.3:a:okta:hyperdrive:*:*:*:*:*:*:*:*
Vendors & Products Okta hyperdrive

Sun, 13 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Okta
Okta okta Hyperdrive Agent
Vendors & Products Okta
Okta okta Hyperdrive Agent

Thu, 10 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Description The Okta Hyperdrive agent plugin returns a success response without a signed SAML assertion when the organization's policy requires no MFA for a given user. The response contains only a bare boolean validation indicator with no cryptographic artifact, resulting in an unverifiable authentication verdict being delivered to the relying application.
Title Improper Authentication Verification in the Okta Hyperdrive Agent MFA Response Handling
Weaknesses CWE-303
References
Metrics cvssV3_1

{'score': 5.6, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:N/I:H/A:N'}


Subscriptions

Okta Hyperdrive Okta Hyperdrive Agent
cve-icon MITRE

Status: PUBLISHED

Assigner: Okta

Published:

Updated: 2026-09-10T14:39:42.613Z

Reserved: 2026-08-24T22:04:00.475Z

Link: CVE-2026-78629

cve-icon Vulnrichment

Updated: 2026-09-10T14:39:37.874Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T21:18:41.347

Modified: 2026-09-22T20:06:42.593

Link: CVE-2026-78629

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-13T20:06:50Z

Weaknesses
  • CWE-303

    Incorrect Implementation of Authentication Algorithm