Identity and access management
Okta advisories: every record the registers tie to its products
In one line
15 advisories are attributed to Okta products in this record, covering February 2022 to December 2025, and none of them appears in the CISA catalogue of known exploited vulnerabilities. A further 17 register entries mention Okta without naming one of its products as affected, and are excluded rather than counted. Each entry below links to the register that published it.
Attributed
15
tied to a named product
Known exploited
0
in the CISA catalogue
Rated critical
0
by the register
Last checked
Jul 24, 2026
sources re-queried
Why this list is shorter than a CVE mirror
The registers are searched by keyword, so a search for a company name returns advisories that merely mention it. A mirror publishes those. This page does not: an entry appears only when the register itself ties it to a product of Okta, through a reference on the vendor's own domain, the vendor named as the assigning authority, or the affected product list naming it.
17 entries did not clear that bar and are not shown. That is the difference, and it is deliberate: a page that lists another company's vulnerability under this heading is wrong in the way that matters most.
12 of the 15 records carry a CVSS base score from the register. Where none is published, none is shown, and no score is estimated.
The full list, most recently exploited and most recent first
Records held by several registers are folded into one entry with a link to each, so the same vulnerability is not counted twice. Entries listed in the CISA catalogue of known exploited vulnerabilities are shown first, because that is the one flag on this page that changes what a reader should do next.
- CVE-2025-67505highCVSS 8.4Dec 10, 2025
Okta Java Management SDK facilitates interactions with the Okta management API.
- CVE-2025-66033mediumCVSS 5.3Dec 10, 2025
Okta Java Management SDK facilitates interactions with the Okta management API.
- CVE-2025-7371mediumCVSS 6.8Jul 22, 2025
Okta On-Premises Provisioning (OPP) agents log certain user data during administrator-initiated password resets.
- CVE-2024-9875highCVSS 7.1Nov 20, 2024
Okta Privileged Access server agent (SFTD) versions 1.82.0 to 1.84.0 are affected by a privilege escalation vulnerability when the sudo command bundles feature is enabled.
- CVE-2024-9191highCVSS 7.1Nov 01, 2024
The Okta Device Access features, provided by the Okta Verify agent for Windows, provides access to the OktaDeviceAccessPipe, which enables attackers in a compromised device to retrieve…
- CVE-2024-10327highCVSS 8.1Oct 24, 2024
A vulnerability in Okta Verify for iOS versions 9.25.1 (beta) and 9.27.0 (including beta) allows push notification responses through the iOS ContextExtension feature allowing the…
- CVE-2024-7061mediumCVSS 5.5Aug 07, 2024
Okta Verify for Windows is vulnerable to privilege escalation through DLL hijacking.
- CVE-2024-0981highCVSS 7.1Jul 23, 2024
Okta Browser Plugin versions 6.5.0 through 6.31.0 (Chrome/Edge/Firefox/Safari) are vulnerable to cross-site scripting.
- CVE-2024-0980highCVSS 7.1Mar 27, 2024
The Auto-update service for Okta Verify for Windows is vulnerable to two flaws which in combination could be used to execute arbitrary code.
- CVE-2023-0392lowCVSS 3.9Nov 08, 2023
The LDAP Agent Update service with versions prior to 5.18 used an unquoted path, which could allow arbitrary code execution.
- CVE-2023-0093highCVSS 8.8Mar 06, 2023
Okta Advanced Server Access Client versions 1.13.1 through 1.65.0 are vulnerable to command injection due to the third party library webbrowser.
- CVE-2022-3145mediumCVSS 4.7Jan 12, 2023
An open redirect vulnerability exists in Okta OIDC Middleware prior to version 5.0.0 allowing an attacker to redirect a user to an arbitrary URL.
- CVE-2022-1697Sep 06, 2022
Okta Active Directory Agent versions 3.8.0 through 3.11.0 installed the Okta AD Agent Update Service using an unquoted path.
- CVE-2022-1030Mar 23, 2022
Okta Advanced Server Access Client for Linux and macOS prior to version 1.58.0 was found to be vulnerable to command injection via a specially crafted URL.
- CVE-2022-24295Feb 21, 2022
Okta Advanced Server Access Client for Windows prior to version 1.57.0 was found to be vulnerable to command injection via a specially crafted URL.
Which registers contributed
| Register | Operated by | Entries | Latest |
|---|---|---|---|
| European Vulnerability Database | ENISA, European Union | 27 | Jul 14, 2026 |
| National Vulnerability Database | NIST, United States Department of Commerce | 8 | Jul 14, 2026 |
The entry counts here are the raw register totals for Okta, before attribution. They are larger than the list above for exactly that reason.
Questions this page answers
How many vulnerabilities does Okta have?
15 advisories in this record are tied by a register to a product of Okta. That is not the same as the number of vulnerabilities the products contain, and no public source knows that number. It is the count of what has been found, disclosed and published, which depends on how much the products are examined and how openly the vendor discloses.
Are any Okta vulnerabilities being actively exploited?
None of the 15 records here appears in the CISA catalogue of known exploited vulnerabilities. That catalogue is not exhaustive: it lists what CISA has confirmed as exploited, so absence from it is not proof that nothing has been exploited.
Why does this page show fewer CVEs for Okta than other sites?
Because a keyword search for a company name returns advisories about other companies' products that mention it in passing, and this page excludes those. 17 register entries name Okta without naming one of its products as affected. A mirror that lists them produces a longer page and a wrong number.
Where do the Okta advisories on this page come from?
From European Vulnerability Database (ENISA, European Union); National Vulnerability Database (NIST, United States Department of Commerce). Every entry links back to the register that published it, and carries the date that register states. Where the same vulnerability is held by several registers it is shown once with a link to each, rather than counted twice.
Does a long advisory list mean Okta is insecure?
No. A register records what researchers found and what the vendor disclosed, so a widely deployed product with a working disclosure process accumulates more entries than one nobody examines. A short list can equally mean a small install base or a vendor that publishes little. This page reports the record and does not rate the vendor, because whether this is acceptable depends on your risk appetite, your compliance scope and the alternatives you are weighing.
A list of advisories is not a risk assessment
What matters is which of these touch the components you actually run, in the configuration you actually run them in, and whether that is acceptable next to the alternatives on your shortlist. DecisionOS reads the same pool against the criteria of a real decision and produces a memo that holds up in front of a board and an auditor.
