CVE-2024-9875

HIGH

Okta Privileged Access server agent <1.84.0 - Privilege Escalation

Title source: llm
STIX 2.1

Description

Okta Privileged Access server agent (SFTD) versions 1.82.0 to 1.84.0 are affected by a privilege escalation vulnerability when the sudo command bundles feature is enabled. To remediate this vulnerability, upgrade the Okta Privileged Access server agent (SFTD) to version 1.87.1 or greater.

Scores

CVSS v3 7.1
EPSS 0.0024
EPSS Percentile 14.8%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-20
Status published
Products (1)
Okta/Okta Privileged Access Server Agent (SFTD) 1.82.0 - 1.84.0
Published Nov 21, 2024
Tracked Since Feb 18, 2026