CVE-2026-78552
Validation Bypass in Okta Access Gateway Custom Directives
CVSS Score
6.0
EPSS Score
0.0%
EPSS Percentile
0th
The Okta Access Gateway does not apply its Lua directive restriction to the application-level custom configuration field. The field is interpolated directly into the nginx server block without inspection, resulting in execution of injected directives.
| CWE | CWE-693 |
| Vendor | okta |
| Product | okta access gateway |
| Published | Sep 8, 2026 |
| Last Updated | Sep 10, 2026 |
Stay Ahead of the Next One
Get instant alerts for okta okta access gateway
Be the first to know when new medium vulnerabilities affecting okta okta access gateway are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:L Attack Vector
Network
Attack Complexity
Low
Privileges Required
High
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
High
Availability
Low
Affected Versions
Okta / Okta Access Gateway
0 < 2026.9.1