Insufficient Label Validation in Okta Access Gateway Configuration
CVE-2026-78625

6.7MEDIUM

Key Information:

Vendor

Okta

Vendor
CVE Published:
8 September 2026

What is CVE-2026-78625?

The Okta Access Gateway has a significant issue where it fails to properly sanitize dashboard label values prior to writing them into generated PHP configuration files. This oversight allows for manipulation of these values, which, when included in authentication requests, can lead to unauthorized execution of commands with the privileges of the web server process. As a result, an attacker could potentially exploit this flaw to gain access to sensitive information or further compromise the system.

Affected Version(s)

Okta Access Gateway 0 < 2026.9.1

References

CVSS V3.1

Score:
6.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.