Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

Okta Hyperdrive agent plugin authentication and logging vulnerabilities

Two vulnerabilities were discovered in the Okta Hyperdrive agent plugin: one returns unverified authentication responses without signed SAML assertions when MFA is not required, and another writes decoded SAML bearer assertions to local log files, exposing authentication credentials to local users.

Disclosed 8 September 2026 · Record updated 13 September 2026

Impact

Authentication bypass via unverified SAML responses and exposure of SAML credentials in local logs to unauthorized local users

Our coverage

No articles linked to this incident yet.

Sources

  1. github.comhttps://github.com/advisories/GHSA-p4wq-g97j-pcf5
  2. github.comhttps://github.com/advisories/GHSA-7x42-7j3m-qc6m