CVE-2026-77585
Okta Privileged Access Client0/100
exploitation likelihood
CVSS5.3
EPSS0.1%
KEVNone
The Okta Privileged Access client does not reject a leading hyphen in the username portion of an SSH target. As a result, the value may be interpreted as a command-line option by the underlying SSH process.
EPSS 0.001 (probability of exploitation) · CVSS base 5.3
Public PoC / Exploit
No public PoC/exploit references indexed yet (Exploit-DB / nuclei). Newly-disclosed CVEs often have none — exploit publication lags disclosure.
References1