CVE-2026-78627: Improper Credential Protection in Okta Hyperdrive Integration Installer Logging
The Okta Hyperdrive Integration installer does not mask the OAuth client secret when passed as an MSI property. The credential is recorded in plaintext in the installer log, the Application Event Log, and the process command line, all of which are readable by an authenticated local user on the workstation.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Okta Hyperdrive Integration pluginto a version that resolves this vulnerability.Fixed in 1.5.2
Event History
Frequently Asked Questions
Who can access the exposed OAuth client secret?
An authenticated local user on the workstation can read the installer log, the Application Event Log, or the installer process command line where the secret is recorded in plaintext.
What must occur for the secret to be exposed?
The OAuth client secret must be supplied to the Okta Hyperdrive Integration installer as an MSI property. The provided data does not indicate that a remote or unauthenticated attacker can retrieve it.
Where should responders look for evidence of exposure?
Review installer logs, the Windows Application Event Log, and process command-line records on workstations where the installer was run. These locations may contain the OAuth client secret in plaintext.