Insufficient Label Validation in Okta Access Gateway Configuration
CVE-2026-78625
6.7MEDIUM
What is CVE-2026-78625?
The Okta Access Gateway has a significant issue where it fails to properly sanitize dashboard label values prior to writing them into generated PHP configuration files. This oversight allows for manipulation of these values, which, when included in authentication requests, can lead to unauthorized execution of commands with the privileges of the web server process. As a result, an attacker could potentially exploit this flaw to gain access to sensitive information or further compromise the system.
Affected Version(s)
Okta Access Gateway 0 < 2026.9.1
