Okta
First CVE: Feb 21, 2022Active for: 4 years
13
CVEs Published
More CVEs Published than 31% of tracked CNAs
3.3
Avg CVEs / Year
More Avg CVEs / Year than 24% of tracked CNAs
7.2
Avg CVSS Score
Higher Avg CVSS Score than 53% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%
Self-Reporting Analysis
Of all the CVEs published by Okta as a CNA, 61.5% affect products that Okta develops as a vendor.
61.5%
38.5%
Self-reported: 8Third-party: 5
Of all the CVEs published that affect products developed by Okta, 66.7% are self-published by Okta as a CNA.
66.7%
33.3%
Self-published: 8Published by other CNAs: 4
Trends Over Time
The number and severity of CVEs published by Okta over time
Volume of CVEsAvg CVSS Base Score
First CVE
Feb 21, 2022
4 years ago
Most Recent CVE
Jul 22, 2025
367 days ago
Top CVEs
All CVEs published by Okta as a CNA, regardless of affected vendor or product.
13 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-24295HIGH Okta Advanced Server Access Client for Windows prior to version 1.57.0 was found to be vulnerable to command injection via a specially crafted URL. | Feb 21, 2022 | 8.8 | 37 | NO | NO |
CVE-2024-10327HIGH A vulnerability in Okta Verify for iOS versions 9.25.1 (beta) and 9.27.0 (including beta) allows push notification responses through the iOS ContextExtension feature allowing the a | Oct 24, 2024 | 8.1 | 26 | NO | NO |
CVE-2024-9191HIGH The Okta Device Access features, provided by the Okta Verify agent for Windows, provides access to the OktaDeviceAccessPipe, which enables attackers in a compromised device to retr | Nov 1, 2024 | 7.8 | 24 | NO | NO |
CVE-2024-0981HIGH Okta Browser Plugin versions 6.5.0 through 6.31.0 (Chrome/Edge/Firefox/Safari) are vulnerable to cross-site scripting. This issue occurs when the plugin prompts the user to save th | Jul 23, 2024 | 7.1 | 23 | NO | NO |
CVE-2024-0980HIGH The Auto-update service for Okta Verify for Windows is vulnerable to two flaws which in combination could be used to execute arbitrary code. | Mar 28, 2024 | 7.1 | 23 | NO | NO |
CVE-2024-7061HIGH Okta Verify for Windows is vulnerable to privilege escalation through DLL hijacking. The vulnerability is fixed in Okta Verify for Windows version 5.0.2. To remediate this vulnerab | Aug 7, 2024 | 7.8 | 22 | NO | NO |
CVE-2023-0093HIGH Okta Advanced Server Access Client versions 1.13.1 through 1.65.0 are vulnerable to command injection due to the third party library webbrowser. An outdated library, webbrowser, us | Mar 6, 2023 | 8.8 | 22 | NO | NO |
CVE-2022-1030HIGH Okta Advanced Server Access Client for Linux and macOS prior to version 1.58.0 was found to be vulnerable to command injection via a specially crafted URL. An attacker, who has kno | Mar 23, 2022 | 8.8 | 22 | NO | NO |
CVE-2025-7371MEDIUM Okta On-Premises Provisioning (OPP) agents log certain user data during administrator-initiated password resets. This vulnerability allows an attacker with access to the local serv | Jul 22, 2025 | 6.8 | 19 | NO | NO |
CVE-2024-9875HIGH Okta Privileged Access server agent (SFTD) versions 1.82.0 to 1.84.0 are affected by a privilege escalation vulnerability when the sudo command bundles feature is enabled. To remed | Nov 21, 2024 | 7.1 | 19 | NO | NO |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA13 CVEs
23%
69%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local5 (38.5%)
Network7 (53.8%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network1 (7.7%)
Attack Complexity
Low11 (84.6%)
High2 (15.4%)
Unknown0 (0.0%)
User Interaction
None7 (53.8%)
Unknown0 (0.0%)
Required6 (46.2%)
Privileges Required
Low4 (30.8%)
High3 (23.1%)
None6 (46.2%)
Unknown0 (0.0%)
Exploit Exposure
Signals from CVEs in this cna scope (13 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
An overview of all social media posts that mention a CVE ID published by Okta as a CNA.
Media Mentions
Media articles that mention a CVE ID published by Okta as a CNA — matched by CVE ID, not by organization name.