← Back to CVE search

CVE-2026-77585

Okta Privileged Access

Description

The Okta Privileged Access client does not reject a leading hyphen in the username portion of an SSH target. As a result, the value may be interpreted as a command-line option by the underlying SSH process.

CVSS 5.3EPSS 0.10200000000000001%Risk 0.53
View source
Published
2026-08-25 20:17:06
Affected versions
unknown
Type
Critical software
Last modified
2026-08-26 20:18:02
Vector
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:L/A:N