CVE-2026-78629: Okta Hyperdrive

Medium severity, CVSS 5.5. EPSS: 0.1% chance of exploitation in the next 30 days.

The Okta Hyperdrive agent plugin returns a success response without a signed SAML assertion when the organization's policy requires no MFA for a given user. The response contains only a bare boolean validation indicator with no cryptographic artifact, resulting in an unverifiable authentication verdict being delivered to the relying application.

Affected products

  • Okta Hyperdrive: from 1.2.0, before 1.5.2 (fixed in 1.5.2)

Published 2026-09-08. Last modified 2026-09-22.