CVE-2026-78629
The Okta Hyperdrive agent plugin returns a success response without a signed SAML assertion when the organization's policy requires no MFA for a given user. The response contains only a bare boolean validation indicator with no cryptographic artifact, resulting in an unverifiable authentication verdict being delivered to the relying application.
- Published Sep 8, 2026
- CVSS 5.5 medium
- 0.1% chance of exploitation in the next 30 days (EPSS)