logo

Okta Fixes Critical Vulnerability Allowing Sign-On Policy Bypass

ID: f7142bf6-9195-5615-ae7a-c2d4ec1763da

STIX ID: report--f7142bf6-9195-5615-ae7a-c2d4ec1763da

Feed Name: HackRead

Threat Score
60/100

Date Published: 2024-10-07

Date Updated: 2026-04-22

Author: Waqas

...
...

Okta patched a vulnerability in its Okta Classic product that could have allowed attackers to bypass application-specific sign-on policies (including device-type restrictions, network zones, and some authentication requirements) if they had valid credentials and used an "unknown" user-agent; the issue stemmed from a July 17, 2024 update, was identified on September 27, 2024, and fixed on October 4, 2024, and Okta advised customers to review logs for unexpected successful authentications and other indicators.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.