VYPR

Privileged Access

by Okta

CVEs (2)

  • CVE-2026-77585MedAug 25, 2026
    risk 0.34cvss 5.3epss 0.00

    The Okta Privileged Access client does not reject a leading hyphen in the username portion of an SSH target. As a result, the value may be interpreted as a command-line option by the underlying SSH process.

  • CVE-2026-78635MedSep 8, 2026
    risk 0.33cvss 5.0epss 0.00

    The Okta Privileged Access client URL handler does not insert an option terminator before appending the target value to the command-line arguments. When a scaleft:// protocol handler link contains a value beginning with a hyphen, the underlying CLI framework interprets it as a…