PentestingHere
Log in Join
[LOW] · Bugcrowd P4 · Unresolved

MFA Enrollment Policy Bypass via Direct POST to /idp/idx/skip

Abdulrahman Zourob Abdulrahman Zourob ████████ 16 Aug 2026

Found and reported an MFA enrollment policy bypass in Okta.

The issue allowed an authenticated user to bypass a mandatory MFA enrollment requirement by directly sending a POST /idp/idx/skip request during the enrollment flow.

Even with the authenticator policy configured as Required with Grace Period = None, the server accepted the skip request and issued a fully authenticated session without completing the required MFA enrollment.

Impact:

  • Mandatory MFA enrollment could be bypassed
  • Users could reach an authenticated session without completing the required second factor
  • The issue was validated and reproduced by Bugcrowd/Okta