[LOW]
·
Bugcrowd P4
·
Unresolved
MFA Enrollment Policy Bypass via Direct POST to /idp/idx/skip
Found and reported an MFA enrollment policy bypass in Okta.
The issue allowed an authenticated user to bypass a mandatory MFA enrollment requirement by directly sending a POST /idp/idx/skip request during the enrollment flow.
Even with the authenticator policy configured as Required with Grace Period = None, the server accepted the skip request and issued a fully authenticated session without completing the required MFA enrollment.
Impact:
- Mandatory MFA enrollment could be bypassed
- Users could reach an authenticated session without completing the required second factor
- The issue was validated and reproduced by Bugcrowd/Okta