CVE-2026-77585

Okta Privileged Access Client
0/100
exploitation likelihood
CVSS5.3
EPSS0.1%
KEVNone
The Okta Privileged Access client does not reject a leading hyphen in the username portion of an SSH target. As a result, the value may be interpreted as a command-line option by the underlying SSH process.
EPSS 0.001 (probability of exploitation) · CVSS base 5.3
Public PoC / Exploit

No public PoC/exploit references indexed yet (Exploit-DB / nuclei). Newly-disclosed CVEs often have none — exploit publication lags disclosure.

References1