
Okta has patched a critical security vulnerability affecting its classic product that could allow attackers to bypass application-specific sign-on policies.
The vulnerability was initially identified on September 27, 2024, and after an internal investigation, determined that it had originated from a software update rolled out on July 17, 2024 afrecting Okta Classic and impacted organizations that had configured application-specific sign-on policies, especially those that relied on device-type restrictions or additional conditions outside the platform’s Global Session Policy
An attacker would need to meet several conditions to carry out a successful attack. First, the attacker needed access to valid credentials—either through phishing, credential stuffing, or brute-force attacks. Second, the organization had to be using application-specific sign-on policies.
Also, the attacker had to be using a device or script that Okta evaluated as an “unknown” user-agent type, which might evade detection by standard device-type restrictions. Once these conditions were met, the attacker might have bypassed sign-on policies that typically require additional layers of authentication or device verification.
Okta has provided specific search recommendations
- Look for unexpected successful authentication events where the device type was flagged as “unknown.”
- Search for unsuccessful authentication attempts, which could indicate credential-based attacks preceding a successful login.
- Organizations were encouraged to monitor for deviations in user behavior, such as unfamiliar IP addresses, geolocations, or access times that could signal unauthorized activity

