Execution Vulnerability in Okta Access Gateway
CVE-2026-78552
6MEDIUM
What is CVE-2026-78552?
The Okta Access Gateway has a vulnerability that allows an attacker to exploit the application-level custom configuration field. This field does not have the necessary restrictions applied to its Lua directives, allowing unauthorized commands to be interpolated directly into the nginx server block. As a result, attackers can inject and execute arbitrary directives, potentially leading to severe security risks.
Affected Version(s)
Okta Access Gateway 0 < 2026.9.1
