Impact
The URL handler for the Okta Privileged Access client fails to insert an option terminator before appending the target value to the command‑line arguments. When a scaleft:// link contains a value that begins with a hyphen, the CLI framework treats that value as a command‑line flag instead of a normal argument, which can alter the SSH client’s behavior in unforeseen ways. This flaw potentially allows an attacker to influence how the SSH connection is established, possibly bypassing expected settings or enabling other unintended actions, thereby impacting the confidentiality, integrity, or availability of the SSH service.
Affected Systems
Any installation of the Okta Privileged Access Client that has not been updated to version 1.113.0 is vulnerable. The vulnerability is specific to the Okta Privileged Access Client and does not apply to other Okta products or external SSH clients.
Risk and Exploitability
The CVSS score of 5 indicates the flaw is considered moderate in severity. No EPSS score is provided, so the likelihood of exploitation is uncertain. The vulnerability is not listed in the CISA KEV catalog, suggesting it is not a known, actively exploited weakness. The likely attack path requires an attacker to supply a malicious scaleft:// link that the user opens, which then triggers the mis‑parsed flag. If an attacker can convince a user to click such a link—via phishing or an otherwise compromised web page—the altered SSH client behavior could be exploited. The absence of publicly known exploitation reduces immediate risk but mitigates a local attack vector that could lead to severe operational impact.
OpenCVE Enrichment