CVE-2026-78635: Okta Privileged Access Client
Medium severity, CVSS 5.0. EPSS: 0.2% chance of exploitation in the next 30 days.
The Okta Privileged Access client URL handler does not insert an option terminator before appending the target value to the command-line arguments. When a scaleft:// protocol handler link contains a value beginning with a hyphen, the underlying CLI framework interprets it as a command-line flag, causing unintended modification of the SSH client's behavior.
Affected products
- Okta Okta Privileged Access Client: from 1.18.0, before 1.113.0 (fixed in 1.113.0)
Published 2026-09-08. Last modified 2026-09-10.