{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-78629","assignerOrgId":"59b22baa-87b2-4371-8e4a-e080df12f74a","state":"PUBLISHED","assignerShortName":"Okta","dateReserved":"2026-08-24T22:04:00.475Z","datePublished":"2026-09-08T20:14:27.716Z","dateUpdated":"2026-09-10T14:39:42.613Z"},"containers":{"cna":{"providerMetadata":{"orgId":"59b22baa-87b2-4371-8e4a-e080df12f74a","shortName":"Okta","dateUpdated":"2026-09-08T20:14:27.716Z"},"title":"Improper Authentication Verification in the Okta Hyperdrive Agent MFA Response Handling","problemTypes":[{"descriptions":[{"lang":"en","description":"Incorrect Implementation of Authentication Algorithm","cweId":"CWE-303"}]}],"affected":[{"vendor":"Okta","product":"Okta Hyperdrive Agent","versions":[{"version":"1.2.0","status":"affected","lessThan":"1.5.2","versionType":"semver"}],"defaultStatus":"unaffected"}],"descriptions":[{"lang":"en","value":"The Okta Hyperdrive agent plugin returns a success response without a signed SAML assertion when the organization's policy requires no MFA for a given user. The response contains only a bare boolean validation indicator with no cryptographic artifact, resulting in an unverifiable authentication verdict being delivered to the relying application."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:N/I:H/A:N","baseScore":5.6,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"}}],"solutions":[{"lang":"en","value":"Upgrade the Okta Hyperdrive agent to version 1.5.2 or greater."}],"references":[{"url":"https://trust.okta.com/security-advisories/improper-authentication-verification-in-the-okta-hyperdrive-agent-mfa-response-handling-cve-2026-78629"}]},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2026-09-10T14:38:49.813878Z","id":"CVE-2026-78629","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-09-10T14:39:42.613Z"}}]}}