Executive brief
Okta Access Gateway is a network appliance that manages secure access to applications for enterprise users. A validation bypass vulnerability allows authenticated administrators to inject arbitrary nginx directives into application configurations, potentially compromising the security controls protecting corporate applications and user data.
Technical details
The vulnerability is a protection mechanism bypass (CWE-693) in the Okta Access Gateway's configuration handling. The appliance fails to apply Lua directive restrictions to the application-level custom configuration field, instead interpolating user-supplied input directly into the nginx server block without inspection. This allows an authenticated administrator with privileges to create or modify application configurations to inject malicious nginx directives. The attack requires authentication with administrative privileges and application configuration reload. The vulnerability is resolved in version 2026.9.1 and later.
Affected products
- Okta Access Gateway prior to 2026.9.1
Timeline
- 2026-09-08: disclosed