CVE-2023-0392: Okta LDAP Agent

Medium severity, CVSS 6.7. EPSS: 0.2% chance of exploitation in the next 30 days.

The LDAP Agent Update service with versions prior to 5.18 used an unquoted path, which could allow arbitrary code execution.

Affected products

  • Okta LDAP Agent: before 5.18 (fixed in 5.18)

Published 2023-11-08. Last modified 2026-06-17.