Improper Input Sanitization in Okta Access Gateway Affecting LDAP Configuration
CVE-2026-78579

6.8MEDIUM

Key Information:

Vendor

Okta

Vendor
CVE Published:
8 September 2026

What is CVE-2026-78579?

The Okta Access Gateway is susceptible to an input validation issue where SAML assertion attribute values are improperly sanitized before being included in LDAP search filters. This flaw allows raw values to be directly inserted into filter strings, resulting in unintended alterations to query logic during LDAP operations. This could potentially lead to incorrect access controls or information disclosure within the LDAP datastore.

Affected Version(s)

Okta Access Gateway 0 < 2026.9.1

References

CVSS V3.1

Score:
6.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.