CVE-2026-78626
The Okta Access Gateway improperly handles input sanitization and regular expression evaluation within its Protected Rule authorization check, resulting in an authorization bypass when an administrator has explicitly configured a Protected Rule policy on one or more application resources.
- Published Sep 8, 2026
- CVSS 6.5 medium
- 0.4% chance of exploitation in the next 30 days (EPSS)