CVE-2026-78627: Improper Credential Protection in Okta Hyperdrive Integration Installer Logging

Published Sep 8, 2026
·
Updated

The Okta Hyperdrive Integration installer does not mask the OAuth client secret when passed as an MSI property. The credential is recorded in plaintext in the installer log, the Application Event Log, and the process command line, all of which are readable by an authenticated local user on the workstation.

Affected Software

1 affected component
Okta Okta Hyperdrive Integration Installer

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Okta Hyperdrive Integration plugin to a version that resolves this vulnerability.

    Fixed in 1.5.2

Event History

Sep 8, 2026
CVE Published
via MITRE·08:12 PM
Data Sourced
via MITRE·08:12 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·08:18 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can access the exposed OAuth client secret?

An authenticated local user on the workstation can read the installer log, the Application Event Log, or the installer process command line where the secret is recorded in plaintext.

2

What must occur for the secret to be exposed?

The OAuth client secret must be supplied to the Okta Hyperdrive Integration installer as an MSI property. The provided data does not indicate that a remote or unauthenticated attacker can retrieve it.

3

Where should responders look for evidence of exposure?

Review installer logs, the Windows Application Event Log, and process command-line records on workstations where the installer was run. These locations may contain the OAuth client secret in plaintext.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203