MEDIUMVulnerability
CVE-2026-78631
The Okta Hyperdrive Agent writes the decoded SAML bearer assertion to a local application log file at the default log level on every successful MFA completion. This insertion of sensitive information into the log file makes a live authentication credential readable by any local user with access to the log file.
Properties
- severity
- MEDIUM
- score
- 5.3
- cve_id
- CVE-2026-78631
- signal_observed_at
- 2026-09-23T04:35:38+00:00
- vector
- CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:N
- published_at
- 2026-09-08T21:18:41.570
- last_modified
- 2026-09-22T20:02:04.043
Related Entities (3)
HAS_WEAKNESS (1)
→[Weakness]Insertion of Sensitive Information into Log File
DESCRIBED_BY (1)
→[Source]NVD
AFFECTS_PRODUCT (1)
→[Product]
Explore deeper with Ninja Signal's threat intelligence graph