logo

Okta Fixes Auth Bypass Bug After 3-Month Lull

ID: bf4cdf0f-e72f-5d20-b3c3-0d2ed6995824

STIX ID: report--bf4cdf0f-e72f-5d20-b3c3-0d2ed6995824

Feed Name: Dark Reading

Threat Score
35/100

Date Published: 2024-11-04

Date Updated: 2026-04-21

Author: Dark Reading Staff

...
...

Okta patched an AD/LDAP delegated authentication bypass that could allow authentication using only a username when specific conditions were met (including usernames of 52+ characters, a cached prior authentication, and an unreachable AD/LDAP agent). The flaw, found Oct. 30 after roughly three months in the system, has been fixed; Okta advised customers to review logs since July 23 and implement MFA, and it is unclear whether the bug was exploited in the wild.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.