{"record":"Okta evidence record","url":"https://nexalign.io/vendors/okta","vendor":{"slug":"okta","name":"Okta","domain":"okta.com","category":"iam","categoryLabel":"Identity and access management"},"lastChecked":"2026-07-24T10:17:29.372Z","coverage":{"earliest":"2009-12-18T18:00:00.000Z","latest":"2026-07-24T04:52:02.726Z"},"terms":{"isRanking":false,"isRating":false,"statesSuitability":false,"note":"This is a record of what public sources hold about a named company. It states no ranking, no rating and no suitability verdict, and none may be derived from it. An absent or small record means the public registers publish little under that name; it is not evidence that a product is secure. A larger advisory count generally reflects wider deployment and more scrutiny rather than a weaker product.","licence":"https://nexalign.io/vendors#licence","corrections":"info@nexalign.io"},"totals":{"evidenceItems":83,"kindsOfSource":6,"attributedAdvisories":15,"knownExploited":0,"registerEntriesNotAttributable":17,"practitionerThreads":13,"independentItems":4,"vendorPublishedItems":2,"shareFromSourcesTheVendorDoesNotControl":0.66},"sources":[{"source":"European Vulnerability Database","operator":"ENISA, European Union","classification":"authoritative","items":27,"latest":"2026-07-14T15:02:09.000Z"},{"source":"National Vulnerability Database","operator":"NIST, United States Department of Commerce","classification":"authoritative","items":8,"latest":"2026-07-14T15:16:55.673Z"},{"source":"Engineering discussions","operator":"Hacker News, public threads","classification":"independent","items":10,"latest":"2026-01-25T01:07:30.000Z"},{"source":"Practitioner discussions","operator":"Reddit, public threads","classification":"independent","items":6,"latest":"2026-04-29T07:46:45.000Z"},{"source":"Analyst, review and reference sources","operator":"Recognised analysts, review marketplaces and technology press","classification":"independent","items":4,"latest":"2026-07-17T10:21:19.454Z"},{"source":"The vendor's own documentation","operator":"Vendor website, indexed by nexalign","classification":"vendor-controlled","items":28,"latest":"2026-07-24T04:52:02.726Z"}],"advisories":{"shown":6,"total":15,"truncated":true,"fullList":"https://nexalign.io/vendors/okta/advisories","items":[{"id":"CVE-2025-67505","description":"Okta Java Management SDK facilitates interactions with the Okta management API.","severity":"high","cvss":8.4,"knownExploited":false,"date":"2025-12-10T23:15:48.667Z","sources":["https://nvd.nist.gov/vuln/detail/CVE-2025-67505","https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-202630"]},{"id":"CVE-2025-66033","description":"Okta Java Management SDK facilitates interactions with the Okta management API.","severity":"medium","cvss":5.3,"knownExploited":false,"date":"2025-12-10T22:16:27.520Z","sources":["https://nvd.nist.gov/vuln/detail/CVE-2025-66033","https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-202632"]},{"id":"CVE-2025-7371","description":"Okta On-Premises Provisioning (OPP) agents log certain user data during administrator-initiated password resets.","severity":"medium","cvss":6.8,"knownExploited":false,"date":"2025-07-22T16:15:34.890Z","sources":["https://nvd.nist.gov/vuln/detail/CVE-2025-7371","https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-22337"]},{"id":"CVE-2024-9875","description":"Okta Privileged Access server agent (SFTD) versions 1.82.0 to 1.84.0 are affected by a privilege escalation vulnerability when the sudo command bundles feature is enabled.","severity":"high","cvss":7.1,"knownExploited":false,"date":"2024-11-20T22:23:15.000Z","sources":["https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-49852"]},{"id":"CVE-2024-9191","description":"The Okta Device Access features, provided by the Okta Verify agent for Windows, provides access to the OktaDeviceAccessPipe, which enables attackers in a compromised device to retrieve…","severity":"high","cvss":7.1,"knownExploited":false,"date":"2024-11-01T21:21:11.000Z","sources":["https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-49780"]},{"id":"CVE-2024-10327","description":"A vulnerability in Okta Verify for iOS versions 9.25.1 (beta) and 9.27.0 (including beta) allows push notification responses through the iOS ContextExtension feature allowing the…","severity":"high","cvss":8.1,"knownExploited":false,"date":"2024-10-24T20:17:59.000Z","sources":["https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-33040"]}]},"practitionerThreads":{"shown":5,"total":13,"truncated":true,"items":[{"title":"Want to move from Okta to Entra but can't figure out how to do it without breaking everything","context":"r/sysadmin","url":"https://www.reddit.com/r/sysadmin/comments/1s7ig2c/want_to_move_from_okta_to_entra_but_cant_figure/","date":"2026-03-30T06:03:32.000Z"},{"title":"Why is everyone using Okta as their IDP?","context":"r/sysadmin","url":"https://www.reddit.com/r/sysadmin/comments/1rbxs22/why_is_everyone_using_okta_as_their_idp/","date":"2026-02-22T21:11:12.000Z"},{"title":"ShinyHunters claims Okta customer breaches, leaks data","context":"r/cybersecurity","url":"https://www.reddit.com/r/cybersecurity/comments/1qm4ua4/shinyhunters_claims_okta_customer_breaches_leaks/","date":"2026-01-25T01:07:54.000Z"},{"title":"ShinyHunters claims Okta customer breaches, leaks data belonging to 3 orgs","context":"Hacker News","url":"https://news.ycombinator.com/item?id=46749565","date":"2026-01-25T01:07:30.000Z"},{"title":"Okta's NextJS-0auth troubles","context":"Hacker News","url":"https://news.ycombinator.com/item?id=45963350","date":"2025-11-18T10:17:20.000Z"}]},"independentCoverage":{"shown":4,"total":4,"truncated":false,"items":[{"title":"Okta Platform Reviews, Competitors and Pricing","host":"peerspot.com","url":"https://www.peerspot.com/products/okta-platform-reviews","date":null},{"title":"Okta Reviews, Ratings & Features 2026 | Gartner Peer Insights","host":"gartner.com","url":"https://www.gartner.com/reviews/market/access-management/vendor/okta","date":null},{"title":"Okta, Inc. - Wikipedia","host":"en.wikipedia.org","url":"https://en.wikipedia.org/wiki/Okta,_Inc.","date":null},{"title":"Okta Identity Governance Reviews & Ratings 2026 | Gartner Peer Insights","host":"gartner.com","url":"https://www.gartner.com/reviews/market/identity-governance-administration/vendor/okta/product/okta-identity-governance","date":null}]},"vendorPublished":{"shown":2,"total":2,"truncated":false,"items":[{"title":"Meet Your Okta Lifecycle Management Expert, Pragya Seth","url":"https://www.okta.com/resources/videos/meet-your-okta-lifecycle-management-expert-pragya-seth/","date":"2026-07-24T04:52:02.726Z"},{"title":"Using Okta for Hybrid Microsoft AAD Join","url":"https://www.okta.com/resources/whitepapers/using-okta-for-hybrid-microsoft-aad-join/","date":"2026-07-02T22:52:09.094Z"}]},"openQuestions":["A further 17 register entries mention Okta without naming a product of Okta as affected. They are excluded rather than counted as vulnerabilities.","Pricing, contract terms, notice periods and support commitments are not part of any public register. They come from the vendor and belong in a negotiation record.","Certification status such as ISO 27001, SOC 2 or BSI C5 has to be checked against the current certificate and its stated scope. A valid certificate can still exclude the product being bought."]}