Products: 13
    Vulnerabilities: 16
    Known Exploited: 0
    0
    Critical Level Threats
    7
    High Level Threats
    8
    Medium Level Threats
    1
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2026-77585

    Improper Validation of SSH Target in Okta Privileged Access Client

    Last Modified: Aug 28, 2026
    Published: Aug 25, 2026

    CVE-2025-67505

    Race condition in the Okta Java SDK

    Last Modified: Mar 06, 2026
    Published: Dec 10, 2025

    CVE-2025-66033

    Improper Memory Cleanup in the Okta Java SDK

    Last Modified: Mar 06, 2026
    Published: Dec 10, 2025

    CVE-2025-7371

    Okta On-Premises Provisioning (OPP) agents log certain user data during administrator-initiated password resets. This vulnerability allows an attacker with access to the local servers running OPP agents to retrieve user personal information and temporary passwords created during password reset. You are affected by this vulnerability if the following preconditions are met: Local server running OPP agent with versions >=2.2.1 and <= 2.3.0, and User account has had an administrator-initiated password reset while using the affected versions.

    Last Modified: Apr 15, 2026
    Published: Jul 22, 2025

    CVE-2024-9875

    Okta Privileged Access server agent (SFTD) versions 1.82.0 to 1.84.0 are affected by a privilege escalation vulnerability when the sudo command bundles feature is enabled. To remediate this vulnerability, upgrade the Okta Privileged Access server agent (SFTD) to version 1.87.1 or greater.

    Last Modified: Apr 15, 2026
    Published: Nov 20, 2024
    Items Per Page