Junglewise Threat Intelligence

CVE-2026-78545: Okta Access Gateway code injection in application label

CVE-2026-78545 · Severity: medium · CVSS 6.6 · Published 2026-09-08

Technologies: Okta Access Gateway. Vendors: Okta.

Executive brief

The Okta Access Gateway, a network appliance that manages secure application access, fails to properly validate the application label field before using it in configuration files. An authenticated administrator can inject malicious nginx directives through the label field, allowing them to execute arbitrary code on the gateway and potentially compromise application traffic and customer data.

Technical details

The vulnerability is a code injection flaw (CWE-94) in the Okta Access Gateway appliance. The application label field is not sanitized before being interpolated into nginx server block directives in the generated configuration file. An authenticated administrator with access to application create or update functionality can inject arbitrary nginx directives through the label field, leading to code execution with the privileges of the nginx process. The attack requires high privilege (administrator role) and high complexity, but can result in full compromise of confidentiality, integrity, and availability. The vulnerability is resolved in version 2026.9.1 and later.

Affected products

  • Okta Access Gateway prior to 2026.9.1

Timeline

  • 2026-09-08: disclosed
  • 2026-09-08: patched: Fixed in version 2026.9.1

References

Related threats