Improper Input Handling in Okta Access Gateway Management Console
CVE-2026-78550
6.6MEDIUM
What is CVE-2026-78550?
The Okta Access Gateway management console is susceptible to a vulnerability that enables code execution via unsanitized user input during an authenticated administrator SSH session. When an administrator enters input, the console processes this input using the eval() function without proper sanitization. This oversight allows malicious inputs to be executed directly, potentially compromising the security of the management console and granting attackers unauthorized privileges. Organizations utilizing this product should take immediate steps to mitigate the risks associated with this vulnerability.
Affected Version(s)
Okta Access Gateway 0 < 2026.9.1
