CVE-2026-68873
Insertion of sensitive information into log file in Windows Program Compatibility Assistant Service allows an authorized attacker to disclos
CVSS
5.5
Medium
EPSS
—
KEV
—
Exploit Today
—
0-100
Published: Sep 8, 2026 · Last modified: Sep 8, 2026 · CWE-532 · CWE-908
Not enough EPSS history yet.
Insertion of sensitive information into log file in Windows Program Compatibility Assistant Service allows an authorized attacker to disclose information locally.
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-786315.3 MED—
———The Okta Hyperdrive Agent writes the decoded SAML bearer assertion to a local application log file at the default log level on every successful MFA completion. This insertion of sensitive information into the log file makes a live authentication credential readable by any local user with access to the log file.7hCVE-2026-786277.3 HIG—
———The Okta Hyperdrive Integration installer does not mask the OAuth client secret when passed as an MSI property. The credential is recorded in plaintext in the installer log, the Application Event Log, and the process command line, all of which are readable by an authenticated local user on the workstation.8hCVE-2026-858807.8 HIG—
———Heap-based buffer overflow in Windows ALPC allows an authorized attacker to elevate privileges locally.9hCVE-2026-819585.5 MED—
———Use of uninitialized resource in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.8hCVE-2026-813915.5 MED—
———Use of uninitialized resource in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.8hCVE-2026-800916.5 MED—
———Use of uninitialized resource in Microsoft Office allows an unauthorized attacker to disclose information over a network.8h