Description
The Okta Privileged Access client URL handler does not insert an option terminator before appending the target value to the command-line arguments. When a scaleft:// protocol handler link contains a value beginning with a hyphen, the underlying CLI framework interprets it as a command-line flag, causing unintended modification of the SSH client's behavior.
Published: 2026-09-08
Score: 5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unintended modification of SSH client behavior through malformed URL handling
Action: Patch
AI Analysis

Impact

The URL handler for the Okta Privileged Access client fails to insert an option terminator before appending the target value to the command‑line arguments. When a scaleft:// link contains a value that begins with a hyphen, the CLI framework treats that value as a command‑line flag instead of a normal argument, which can alter the SSH client’s behavior in unforeseen ways. This flaw potentially allows an attacker to influence how the SSH connection is established, possibly bypassing expected settings or enabling other unintended actions, thereby impacting the confidentiality, integrity, or availability of the SSH service.

Affected Systems

Any installation of the Okta Privileged Access Client that has not been updated to version 1.113.0 is vulnerable. The vulnerability is specific to the Okta Privileged Access Client and does not apply to other Okta products or external SSH clients.

Risk and Exploitability

The CVSS score of 5 indicates the flaw is considered moderate in severity. No EPSS score is provided, so the likelihood of exploitation is uncertain. The vulnerability is not listed in the CISA KEV catalog, suggesting it is not a known, actively exploited weakness. The likely attack path requires an attacker to supply a malicious scaleft:// link that the user opens, which then triggers the mis‑parsed flag. If an attacker can convince a user to click such a link—via phishing or an otherwise compromised web page—the altered SSH client behavior could be exploited. The absence of publicly known exploitation reduces immediate risk but mitigates a local attack vector that could lead to severe operational impact.

Generated by OpenCVE AI on September 9, 2026 at 09:25 UTC.

Remediation

Vendor Solution

Upgrade the Okta Privileged Access client to version 1.113.0.


OpenCVE Recommended Actions

  • Upgrade the Okta Privileged Access client to version 1.113.0
  • If an upgrade is not immediately possible, disable or filter incoming scaleft:// URLs to prevent the injection of malicious flags
  • Verify that the client is able to launch SSH connections only with expected parameters, ensuring no unvalidated user input influences the command line

Generated by OpenCVE AI on September 9, 2026 at 09:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 11 Sep 2026 05:15:00 +0000

Type Values Removed Values Added
First Time appeared Okta
Okta okta Privileged Access Client
Vendors & Products Okta
Okta okta Privileged Access Client

Thu, 10 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Description The Okta Privileged Access client URL handler does not insert an option terminator before appending the target value to the command-line arguments. When a scaleft:// protocol handler link contains a value beginning with a hyphen, the underlying CLI framework interprets it as a command-line flag, causing unintended modification of the SSH client's behavior.
Title Improper Input Validation in the Okta Privileged Access SSH Client URL Handler Argument
Weaknesses CWE-88
References
Metrics cvssV3_1

{'score': 5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L'}


Subscriptions

Okta Okta Privileged Access Client
cve-icon MITRE

Status: PUBLISHED

Assigner: Okta

Published:

Updated: 2026-09-10T14:38:28.882Z

Reserved: 2026-08-24T22:06:37.295Z

Link: CVE-2026-78635

cve-icon Vulnrichment

Updated: 2026-09-10T14:38:20.942Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-08T21:18:41.680

Modified: 2026-09-10T15:17:42.800

Link: CVE-2026-78635

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T05:00:12Z

Weaknesses
  • CWE-88

    Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')