{"api_version":"1","generated_at":"2026-09-10T23:25:56+00:00","cve":"CVE-2026-78574","urls":{"html":"https://cve.report/CVE-2026-78574","api":"https://cve.report/api/cve/CVE-2026-78574.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-78574","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-78574"},"summary":{"title":"Improper Assembly Resolution in Okta Hyperdrive Integration Plugin Registry Handling","description":"The Okta Hyperdrive Integration plugin resolves a required assembly using a registry path within the current user's hive without integrity verification. The referenced path is loaded via Assembly.LoadFrom without signature validation, resulting in an unverified assembly executing within the context of the host process or elevated installer.","state":"PUBLISHED","assigner":"Okta","published_at":"2026-09-08 20:18:36","updated_at":"2026-09-10 15:17:41"},"problem_types":["CWE-426","CWE-426 Untrusted Search Path"],"metrics":[{"version":"3.1","source":"psirt@okta.com","type":"Secondary","score":"7.5","severity":"HIGH","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"}},{"version":"3.1","source":"CNA","type":"DECLARED","score":"7.5","severity":"HIGH","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N","data":{"attackComplexity":"HIGH","attackVector":"LOCAL","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"LOW","scope":"CHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N","version":"3.1"}}],"references":[{"url":"https://trust.okta.com/security-advisories/improper-assembly-resolution-in-okta-hyperdrive-integration-plugin-registry-handling-cve-2026-78574","name":"https://trust.okta.com/security-advisories/improper-assembly-resolution-in-okta-hyperdrive-integration-plugin-registry-handling-cve-2026-78574","refsource":"psirt@okta.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-78574","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-78574","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Okta","product":"Okta Hyperdrive Integration Plugin","version":"affected 1.2.0 1.5.2 semver","platforms":[]}],"timeline":[],"solutions":[{"source":"CNA","title":"","value":"Upgrade the Okta Hyperdrive Integration plugin to version 1.5.2 or greater.","time":"","lang":"en"}],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"metrics":[{"other":{"content":{"id":"CVE-2026-78574","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"total"}],"role":"CISA Coordinator","timestamp":"2026-09-10T14:36:30.614100Z","version":"2.0.3"},"type":"ssvc"}}],"providerMetadata":{"dateUpdated":"2026-09-10T14:36:50.101Z","orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP"},"title":"CISA ADP Vulnrichment"}],"cna":{"affected":[{"defaultStatus":"unaffected","product":"Okta Hyperdrive Integration Plugin","vendor":"Okta","versions":[{"lessThan":"1.5.2","status":"affected","version":"1.2.0","versionType":"semver"}]}],"descriptions":[{"lang":"en","value":"The Okta Hyperdrive Integration plugin resolves a required assembly using a registry path within the current user's hive without integrity verification. The referenced path is loaded via Assembly.LoadFrom without signature validation, resulting in an unverified assembly executing within the context of the host process or elevated installer."}],"metrics":[{"cvssV3_1":{"attackComplexity":"HIGH","attackVector":"LOCAL","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"LOW","scope":"CHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N","version":"3.1"}}],"problemTypes":[{"descriptions":[{"cweId":"CWE-426","description":"Untrusted Search Path","lang":"en"}]}],"providerMetadata":{"dateUpdated":"2026-09-08T20:11:43.869Z","orgId":"59b22baa-87b2-4371-8e4a-e080df12f74a","shortName":"Okta"},"references":[{"url":"https://trust.okta.com/security-advisories/improper-assembly-resolution-in-okta-hyperdrive-integration-plugin-registry-handling-cve-2026-78574"}],"solutions":[{"lang":"en","value":"Upgrade the Okta Hyperdrive Integration plugin to version 1.5.2 or greater."}],"title":"Improper Assembly Resolution in Okta Hyperdrive Integration Plugin Registry Handling"}},"cveMetadata":{"assignerOrgId":"59b22baa-87b2-4371-8e4a-e080df12f74a","assignerShortName":"Okta","cveId":"CVE-2026-78574","datePublished":"2026-09-08T20:11:43.869Z","dateReserved":"2026-08-24T20:39:00.874Z","dateUpdated":"2026-09-10T14:36:50.101Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-09-08 20:18:36","lastModifiedDate":"2026-09-10 15:17:41","problem_types":["CWE-426","CWE-426 Untrusted Search Path"],"metrics":{"cvssMetricV31":[{"source":"psirt@okta.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":1.1,"impactScore":5.8}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-09-10T14:36:30.614100Z","id":"CVE-2026-78574","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"78574","Ordinal":"1","Title":"Improper Assembly Resolution in Okta Hyperdrive Integration Plug","CVE":"CVE-2026-78574","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"78574","Ordinal":"1","NoteData":"The Okta Hyperdrive Integration plugin resolves a required assembly using a registry path within the current user's hive without integrity verification. The referenced path is loaded via Assembly.LoadFrom without signature validation, resulting in an unverified assembly executing within the context of the host process or elevated installer.","Type":"Description","Title":"Improper Assembly Resolution in Okta Hyperdrive Integration Plug"}]}}}