Okta Access Gateway
11 known vulnerabilities in Okta Access Gateway, 1 critical, with patch priority, exploit likelihood and the news covering them.
Latest vulnerabilities
- CVE-2026-78630 CVSS 6.7 medium The Okta Access Gateway does not neutralize shell metacharacters in SNMP configuration values before a privileged script uses them to…
- CVE-2026-78626 CVSS 6.5 medium The Okta Access Gateway improperly handles input sanitization and regular expression evaluation within its Protected Rule authorization…
- CVE-2026-78625 CVSS 6.7 medium The Okta Access Gateway does not sanitize dashboard label values before writing them into generated PHP configuration files. The generated…
- CVE-2026-78624 CVSS 4.9 medium The Okta Access Gateway backup restore function does not validate the filename embedded in an encrypted backup payload. This results in…
- CVE-2026-78623 CVSS 9.9 critical The Okta Access Gateway does not sanitize SAML assertion values before interpolating them into database queries in the advanced mode…
- CVE-2026-78620 CVSS 4.9 medium The Okta Access Gateway Kerberos configuration handler does not validate file paths specified in event payloads before writing file…
- CVE-2026-78579 CVSS 6.5 medium The Okta Access Gateway does not sanitize SAML assertion attribute values before interpolating them into LDAP search filters in the LDAP…
- CVE-2026-78560 CVSS 6.5 medium The Okta Access Gateway includes an optional pass-through authentication source that accepts user identity from a client-supplied HTTP…
- CVE-2026-78552 CVSS 4.9 medium The Okta Access Gateway does not apply its Lua directive restriction to the application-level custom configuration field. The field is…
- CVE-2026-78550 CVSS 7.2 high The Okta Access Gateway management console passes user-supplied input to eval() without sanitization during an authenticated administrator…
- CVE-2026-78545 CVSS 7.2 high The Okta Access Gateway does not sanitize the application label field before including it in the generated nginx configuration file. The…