OktaCVE-2026-78552
Okta Access Gateway: protection mechanism failure
Medium6.0CVE-2026-78552 · Published Sep 8, 2026 · updated Sep 23, 2026
The Okta Access Gateway does not apply its Lua directive restriction to the application-level custom configuration field. The field is interpolated directly into the nginx server block without inspection, resulting in execution of injected directives.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Okta Access Gateway Product | < 2026.9.1 | 2026.9.1 |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:L
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-693
More Okta advisories
All Okta| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 8 | Okta Auth0 AD/LDAP Connector: missing authentication | Medium6.7 | No fix yet |
| Sep 8 | Okta Auth0 AD/LDAP Connector: cross-site scripting | Critical9.0 | No fix yet |
| Sep 8 | Okta Auth0 AD/LDAP Connector: code execution | High7.8 | No fix yet |
| Sep 8 | The react-native-auth0 SDK's web platform implementation does not scope its... | Medium6.5 | 5.11.1 |
| Sep 8 | Okta Verify for Windows: link following | Medium6.0 | 7.0.0 |
| Sep 8 | The Okta Hyperdrive agent plugin returns a success response without a signed... | Medium5.6 | 1.5.2 |