The Okta Privileged Access client URL handler does not insert an option terminator before appending the target value to the command-line arguments. When a scaleft:// protocol handler link contains a value beginning with a hyphen, the underlying CLI framework interprets it as a command-line flag, causing unintended modification of the SSH client's behavior.

Project Subscriptions

No data.

Advisories

No advisories yet.

Fixes

Solution

Upgrade the Okta Privileged Access client to version 1.113.0.


Workaround

No workaround given by the vendor.

History

Tue, 08 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Description The Okta Privileged Access client URL handler does not insert an option terminator before appending the target value to the command-line arguments. When a scaleft:// protocol handler link contains a value beginning with a hyphen, the underlying CLI framework interprets it as a command-line flag, causing unintended modification of the SSH client's behavior.
Title Improper Input Validation in the Okta Privileged Access SSH Client URL Handler Argument
Weaknesses CWE-88
References
Metrics cvssV3_1

{'score': 5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: Okta

Published:

Updated: 2026-09-08T20:14:00.691Z

Reserved: 2026-08-24T22:06:37.295Z

Link: CVE-2026-78635

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-08T21:18:41.680

Modified: 2026-09-08T21:18:41.680

Link: CVE-2026-78635

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses