HIGHVulnerability

CVE-2026-78627

The Okta Hyperdrive Integration installer does not mask the OAuth client secret when passed as an MSI property. The credential is recorded in plaintext in the installer log, the Application Event Log, and the process command line, all of which are readable by an authenticated local user on the workstation.

Properties

severity
HIGH
score
7.3
cve_id
CVE-2026-78627
signal_observed_at
2026-09-23T04:35:38+00:00
vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N
published_at
2026-09-08T20:18:38.440
last_modified
2026-09-22T20:10:34.717

Related Entities (3)

HAS_WEAKNESS (1)

[Weakness]Insertion of Sensitive Information into Log File

DESCRIBED_BY (1)

[Source]NVD

AFFECTS_PRODUCT (1)

[Product]

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-78627 — Ninja Signal Threat Intelligence | Ninja Signal