Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Upgrade the Okta Privileged Access client to version 1.113.0.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 10 Sep 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 08 Sep 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Okta Privileged Access client URL handler does not insert an option terminator before appending the target value to the command-line arguments. When a scaleft:// protocol handler link contains a value beginning with a hyphen, the underlying CLI framework interprets it as a command-line flag, causing unintended modification of the SSH client's behavior. | |
| Title | Improper Input Validation in the Okta Privileged Access SSH Client URL Handler Argument | |
| Weaknesses | CWE-88 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: Okta
Published:
Updated: 2026-09-10T14:38:28.882Z
Reserved: 2026-08-24T22:06:37.295Z
Link: CVE-2026-78635
Updated: 2026-09-10T14:38:20.942Z
Status : Awaiting Analysis
Published: 2026-09-08T21:18:41.680
Modified: 2026-09-10T15:17:42.800
Link: CVE-2026-78635
No data.
OpenCVE Enrichment
Updated: 2026-09-09T09:30:08Z