logo

Why the long name? Okta discloses auth bypass bug affecting 52-character usernames

ID: 2e2a211b-ea54-5397-b56a-2e8cdd91943f

STIX ID: report--2e2a211b-ea54-5397-b56a-2e8cdd91943f

Feed Name: The Register (Security)

Threat Score
35/100

Date Published: 2024-11-04

Date Updated: 2026-04-26

Author: Connor Jones

...
...

Okta discovered and fixed a Delegated Authentication vulnerability that could let an attacker authenticate using only a username 52 characters or longer when a bcrypt-based cached login key existed and was used (for example if the AD/LDAP agent was unreachable) and multi-factor authentication was not enabled; the issue was found and patched the same day and customers were advised to check logs and enable phishing-resistant MFA.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.