Okta fixes a flaw present since July 23, 2024, that let users log in under specific circumstances with any password if the account's username had 52+ characters
The vulnerability is fixed now, but Okta said that for three months it could've been used to access accounts with usernames stretching at least 52 characters long.