Impact
The vulnerability lies in the Okta Hyperdrive agent’s MFA response handling. When the organization’s policy allows users without MFA, the agent returns a success response that only contains a plain boolean flag, omitting the signed SAML assertion required for credential verification. Consequently, the relying application receives an authentication verdict that cannot be cryptographically validated, which effectively permits authentication without the intended security checks.
Affected Systems
This issue affects the Okta Hyperdrive Agent plugin used within enterprises that rely on Okta for single sign‑on. The affected component is the Okta Hyperdrive Agent, version prior to 1.5.2. Organizations deploying any version earlier than the fixed release are potentially impacted.
Risk and Exploitability
The CVSS score of 5.6 indicates a moderate impact; the vulnerability is not currently present in the CISA KEV catalog and no EPSS data is available, implying a low to moderate likelihood of exploitation. Attackers would need access to a user session where MFA is not required; if they can trigger the response, they may obtain an authentication token that the relying application accepts as valid. Because the flaw arises from missing cryptographic verification, the risk stems from the application trusting unsigned responses rather than the upstream service.
OpenCVE Enrichment