Improper Authentication in Okta Access Gateway Allowing Arbitrary Identity Session Initiation
CVE-2026-78560

4.8MEDIUM

Key Information:

Vendor

Okta

Vendor
CVE Published:
8 September 2026

What is CVE-2026-78560?

The Okta Access Gateway features an optional pass-through authentication mechanism that lacks adequate cryptographic validation of user identities provided via HTTP headers. If enabled without a properly configured upstream reverse proxy or firewall to sanitize these headers, this vulnerability allows unauthenticated users to inject arbitrary identity values, potentially compromising session integrity and user access to secure resources.

Affected Version(s)

Okta Access Gateway 0 < 2026.9.1

References

CVSS V3.1

Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.