Executive brief
Okta Access Gateway is a security appliance that controls user access to protected applications. When an optional pass-through authentication mode is enabled, the appliance can be tricked into accepting arbitrary user identities from HTTP headers without proper validation. An attacker without valid credentials can impersonate any user and gain unauthorized access to applications, unless the organization has deployed additional network protections to block this attack.
Technical details
The vulnerability is an improper authentication validation issue (CWE-287) in the pass-through authentication source module of Okta Access Gateway. The component accepts user identity claims directly from client-supplied HTTP headers without cryptographic validation or integrity checking. An unauthenticated attacker with network access can craft HTTP requests containing arbitrary identity headers to initiate sessions as any user. This requires the administrator to have explicitly enabled the pass-through authentication source module and the deployment to lack upstream reverse proxy or firewall rules that sanitize/strip client headers. The vulnerability is fixed in version 2026.9.1 and later.
Affected products
- Okta Access Gateway prior to 2026.9.1
Timeline
- 2026-09-08: disclosed