CVE-2026-78631

The Okta Hyperdrive Agent writes the decoded SAML bearer assertion to a local application log file at the default log level on every successful MFA completion. This insertion of sensitive information into the log file makes a live authentication credential readable by any local user with access to the log file.

  • Published Sep 8, 2026
  • CVSS 5.5 medium
  • 0.1% chance of exploitation in the next 30 days (EPSS)

Affected software

CVE-2026-78631 at the National Vulnerability Database