Junglewise Threat Intelligence

CVE-2026-78627: Okta Hyperdrive Integration installer logs OAuth client secret in plaintext

CVE-2026-78627 · Severity: high · CVSS 7.3 · Published 2026-09-08

Technologies: Okta Hyperdrive. Vendors: Okta.

Executive brief

The Okta Hyperdrive Integration installer fails to mask OAuth client secrets when passed as installation parameters. This credential exposure is recorded in installer logs, event logs, and process command lines—all readable by authenticated local users on Windows systems. An attacker with local account access can recover the secret and potentially gain unauthorized access to integrated systems.

Technical details

The vulnerability is a credential exposure issue (CWE-532: Insertion of Sensitive Information into Log File) in the Okta Hyperdrive Integration installer. When an OAuth client secret is passed as an MSI property during installation, it is recorded in plaintext across multiple locations: the installer log, the Windows Application Event Log, and the process command line. The attack vector is local and requires an authenticated local user account on the Windows workstation where the agent is installed. This allows an authenticated attacker to read sensitive credentials and potentially compromise connected systems. The vulnerability affects versions 1.2.0 through 1.5.1 and is fixed in version 1.5.2 or later.

Affected products

  • Okta Hyperdrive Integration 1.2.0 through 1.5.1

Timeline

  • 2026-09-08: disclosed
  • 2026-09-08: patched: Version 1.5.2 or greater

References

Related threats