Improper Authentication in Okta Access Gateway Allowing Arbitrary Identity Session Initiation
CVE-2026-78560
4.8MEDIUM
What is CVE-2026-78560?
The Okta Access Gateway features an optional pass-through authentication mechanism that lacks adequate cryptographic validation of user identities provided via HTTP headers. If enabled without a properly configured upstream reverse proxy or firewall to sanitize these headers, this vulnerability allows unauthenticated users to inject arbitrary identity values, potentially compromising session integrity and user access to secure resources.
Affected Version(s)
Okta Access Gateway 0 < 2026.9.1
