CVE-2026-78627
moderatePlaintext OAuth Client Secret Exposure in Okta Hyperdrive Integration Installer
The Okta Hyperdrive Integration installer fails to mask the OAuth client secret when it is supplied as an MSI property, leaving the credential recorded in plaintext (CWE-532). The exposure occurs whenever the installer runs: the secret is written to the installer log, the Windows Application Event Log, and the process command line. An attacker with any authenticated low-privileged local account on the workstation can read those locations, recover the OAuth client secret, and potentially use it to access or manipulate the associated Okta integration, which the scope-changed CVSS score (C:H/I:L) reflects. Organizations that deployed the Hyperdrive Integration installer to Windows workstations are affected; the disclosure does not specify affected version ranges. No public proof-of-concept exists, the issue is not in CISA KEV, and EPSS puts exploitation probability at 0.1% over 30 days (1st percentile), so no exploitation is currently known.
What to do: Check installer logs, the Windows Application Event Log, and any retained process command-line data (e.g., in EDR/SIEM logs) on workstations where the Hyperdrive Integration installer ran, and rotate any OAuth client secret found in plaintext via the Okta admin console. Deploy the corrected installer per Okta's advisory (fixed version not specified in the available data), and confirm with Okta whether the exposed secret grants broader tenant access before and after rotation.
| Okta Hyperdrive Integration (MSI installer for Windows workstations) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
The Okta Hyperdrive Integration installer does not mask the OAuth client secret when passed as an MSI property. The credential is recorded in plaintext in the installer log, the Application Event Log, and the process command line, all of which are readable by an authenticated local user on the workstation.
- Weakness
- CWE-532
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N
In the news0 stories
No ingested article mentions this CVE yet.