CVE-2026-78626

The Okta Access Gateway improperly handles input sanitization and regular expression evaluation within its Protected Rule authorization check, resulting in an authorization bypass when an administrator has explicitly configured a Protected Rule policy on one or more application resources.

  • Published Sep 8, 2026
  • CVSS 6.5 medium
  • 0.4% chance of exploitation in the next 30 days (EPSS)

Affected software

In the news

CVE-2026-78626 at the National Vulnerability Database