Improper Input Handling in Okta Access Gateway Management Console
CVE-2026-78550

6.6MEDIUM

Key Information:

Vendor

Okta

Vendor
CVE Published:
8 September 2026

What is CVE-2026-78550?

The Okta Access Gateway management console is susceptible to a vulnerability that enables code execution via unsanitized user input during an authenticated administrator SSH session. When an administrator enters input, the console processes this input using the eval() function without proper sanitization. This oversight allows malicious inputs to be executed directly, potentially compromising the security of the management console and granting attackers unauthorized privileges. Organizations utilizing this product should take immediate steps to mitigate the risks associated with this vulnerability.

Affected Version(s)

Okta Access Gateway 0 < 2026.9.1

References

CVSS V3.1

Score:
6.6
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.