CVE-2026-78624
The Okta Access Gateway backup restore function does not validate the filename embedded in an encrypted backup payload. This results in writing file contents to unintended locations on the appliance filesystem.
- Published Sep 8, 2026
- CVSS 4.9 medium
- 0.5% chance of exploitation in the next 30 days (EPSS)