{"api_version":"1","generated_at":"2026-09-10T23:53:43+00:00","cve":"CVE-2026-78627","urls":{"html":"https://cve.report/CVE-2026-78627","api":"https://cve.report/api/cve/CVE-2026-78627.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-78627","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-78627"},"summary":{"title":"Improper Credential Protection in Okta Hyperdrive Integration Installer Logging","description":"The Okta Hyperdrive Integration installer does not mask the OAuth client secret when passed as an MSI property. The credential is recorded in plaintext in the installer log, the Application Event Log, and the process command line, all of which are readable by an authenticated local user on the workstation.","state":"PUBLISHED","assigner":"Okta","published_at":"2026-09-08 20:18:38","updated_at":"2026-09-10 15:17:42"},"problem_types":["CWE-532","CWE-532 Insertion of Sensitive Information into Log File"],"metrics":[{"version":"3.1","source":"psirt@okta.com","type":"Secondary","score":"7.3","severity":"HIGH","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N","baseScore":7.3,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"LOW","availabilityImpact":"NONE"}},{"version":"3.1","source":"CNA","type":"DECLARED","score":"7.3","severity":"HIGH","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N","data":{"attackComplexity":"LOW","attackVector":"LOCAL","availabilityImpact":"NONE","baseScore":7.3,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"LOW","privilegesRequired":"LOW","scope":"CHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N","version":"3.1"}}],"references":[{"url":"https://trust.okta.com/security-advisories/improper-credential-protection-in-okta-hyperdrive-integration-installer-logging-cve-2026-78627","name":"https://trust.okta.com/security-advisories/improper-credential-protection-in-okta-hyperdrive-integration-installer-logging-cve-2026-78627","refsource":"psirt@okta.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-78627","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-78627","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Okta","product":"Okta Hyperdrive Integration Plugin","version":"affected 1.2.0 1.5.2 semver","platforms":[]}],"timeline":[],"solutions":[{"source":"CNA","title":"","value":"Upgrade the Okta Hyperdrive Integration plugin to version 1.5.2 or greater.","time":"","lang":"en"}],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"metrics":[{"other":{"content":{"id":"CVE-2026-78627","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","timestamp":"2026-09-10T14:37:05.638378Z","version":"2.0.3"},"type":"ssvc"}}],"providerMetadata":{"dateUpdated":"2026-09-10T14:37:14.625Z","orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP"},"title":"CISA ADP Vulnrichment"}],"cna":{"affected":[{"defaultStatus":"unaffected","product":"Okta Hyperdrive Integration Plugin","vendor":"Okta","versions":[{"lessThan":"1.5.2","status":"affected","version":"1.2.0","versionType":"semver"}]}],"descriptions":[{"lang":"en","value":"The Okta Hyperdrive Integration installer does not mask the OAuth client secret when passed as an MSI property. The credential is recorded in plaintext in the installer log, the Application Event Log, and the process command line, all of which are readable by an authenticated local user on the workstation."}],"metrics":[{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"LOCAL","availabilityImpact":"NONE","baseScore":7.3,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"LOW","privilegesRequired":"LOW","scope":"CHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N","version":"3.1"}}],"problemTypes":[{"descriptions":[{"cweId":"CWE-532","description":"Insertion of Sensitive Information into Log File","lang":"en"}]}],"providerMetadata":{"dateUpdated":"2026-09-08T20:12:16.468Z","orgId":"59b22baa-87b2-4371-8e4a-e080df12f74a","shortName":"Okta"},"references":[{"url":"https://trust.okta.com/security-advisories/improper-credential-protection-in-okta-hyperdrive-integration-installer-logging-cve-2026-78627"}],"solutions":[{"lang":"en","value":"Upgrade the Okta Hyperdrive Integration plugin to version 1.5.2 or greater."}],"title":"Improper Credential Protection in Okta Hyperdrive Integration Installer Logging"}},"cveMetadata":{"assignerOrgId":"59b22baa-87b2-4371-8e4a-e080df12f74a","assignerShortName":"Okta","cveId":"CVE-2026-78627","datePublished":"2026-09-08T20:12:16.468Z","dateReserved":"2026-08-24T22:04:00.475Z","dateUpdated":"2026-09-10T14:37:14.625Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-09-08 20:18:38","lastModifiedDate":"2026-09-10 15:17:42","problem_types":["CWE-532","CWE-532 Insertion of Sensitive Information into Log File"],"metrics":{"cvssMetricV31":[{"source":"psirt@okta.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N","baseScore":7.3,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2,"impactScore":4.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-09-10T14:37:05.638378Z","id":"CVE-2026-78627","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"78627","Ordinal":"1","Title":"Improper Credential Protection in Okta Hyperdrive Integration In","CVE":"CVE-2026-78627","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"78627","Ordinal":"1","NoteData":"The Okta Hyperdrive Integration installer does not mask the OAuth client secret when passed as an MSI property. The credential is recorded in plaintext in the installer log, the Application Event Log, and the process command line, all of which are readable by an authenticated local user on the workstation.","Type":"Description","Title":"Improper Credential Protection in Okta Hyperdrive Integration In"}]}}}