Okta Hyperdrive agent plugin authentication and logging vulnerabilities
Two vulnerabilities were discovered in the Okta Hyperdrive agent plugin: one returns unverified authentication responses without signed SAML assertions when MFA is not required, and another writes decoded SAML bearer assertions to local log files, exposing authentication credentials to local users.
Disclosed 8 September 2026 · Record updated 13 September 2026
Impact
Authentication bypass via unverified SAML responses and exposure of SAML credentials in local logs to unauthorized local users
Our coverage
No articles linked to this incident yet.
Sources
- github.comhttps://github.com/advisories/GHSA-p4wq-g97j-pcf5
- github.comhttps://github.com/advisories/GHSA-7x42-7j3m-qc6m
