Executive brief
The Okta Access Gateway, a network appliance that manages secure application access, fails to properly validate the application label field before using it in configuration files. An authenticated administrator can inject malicious nginx directives through the label field, allowing them to execute arbitrary code on the gateway and potentially compromise application traffic and customer data.
Technical details
The vulnerability is a code injection flaw (CWE-94) in the Okta Access Gateway appliance. The application label field is not sanitized before being interpolated into nginx server block directives in the generated configuration file. An authenticated administrator with access to application create or update functionality can inject arbitrary nginx directives through the label field, leading to code execution with the privileges of the nginx process. The attack requires high privilege (administrator role) and high complexity, but can result in full compromise of confidentiality, integrity, and availability. The vulnerability is resolved in version 2026.9.1 and later.
Affected products
- Okta Access Gateway prior to 2026.9.1
Timeline
- 2026-09-08: disclosed
- 2026-09-08: patched: Fixed in version 2026.9.1