VulnSea

hyperdrive vulnerabilities

CVEs whose affected-version data names the hyperdrive package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

4 CVEsRSS

CVE-2026-78631Medium· 5.3
2w ago

The Okta Hyperdrive Agent writes the decoded SAML bearer assertion to a local application log file at the default log level on every successful MFA completion

The Okta Hyperdrive Agent writes the decoded SAML bearer assertion to a local application log file at the default log level on every successful MFA completion. This insertion of sensitive information into the log file makes a live authen…

Sunlitokta · hyperdriveEPSS 0.10%via NVD
CVE-2026-78629Medium· 5.6
2w ago

The Okta Hyperdrive agent plugin returns a success response without a signed SAML assertion when the organization's policy requires no MFA for a given user

The Okta Hyperdrive agent plugin returns a success response without a signed SAML assertion when the organization's policy requires no MFA for a given user. The response contains only a bare boolean validation indicator with no cryptogra…

Sunlitokta · hyperdriveEPSS 0.10%via NVD
CVE-2026-78627High· 7.3
2w ago

The Okta Hyperdrive Integration installer does not mask the OAuth client secret when passed as an MSI property

The Okta Hyperdrive Integration installer does not mask the OAuth client secret when passed as an MSI property. The credential is recorded in plaintext in the installer log, the Application Event Log, and the process command line, all of…

Twilightokta · hyperdriveEPSS 0.10%via NVD
CVE-2026-78574High· 7.5
2w ago

The Okta Hyperdrive Integration plugin resolves a required assembly using a registry path within the current user's hive without integrity verification

The Okta Hyperdrive Integration plugin resolves a required assembly using a registry path within the current user's hive without integrity verification. The referenced path is loaded via Assembly.LoadFrom without signature validation, re…

Twilightokta · hyperdriveEPSS 0.10%via NVD
hyperdrive vulnerabilities (CVEs) · VulnSea