Junglewise Threat Intelligence

CVE-2026-78579: Okta Access Gateway LDAP injection in datastore filter

CVE-2026-78579 · Severity: medium · CVSS 6.8 · Published 2026-09-08

Technologies: Okta Access Gateway. Vendors: Okta.

Executive brief

Okta Access Gateway is an identity management appliance that authenticates users and authorizes access to corporate applications. The appliance fails to sanitize SAML assertion attributes before using them in LDAP directory lookups, allowing attackers to manipulate LDAP queries and potentially access unauthorized user records or modify authentication logic.

Technical details

The vulnerability is LDAP injection (CWE-90) in the LDAP datastore filter interpolation component. When an administrator configures an LDAP search filter template that references SAML assertion attributes, the Access Gateway directly interpolates attribute values into the LDAP filter string without sanitization. An attacker who controls a SAML attribute value (e.g., through a compromised IdP or by influencing its contents) can inject LDAP filter syntax to modify query logic. Attack requires authenticated user with control over SAML attributes and an LDAP datastore configured with interpolated search filters. Successful exploitation allows query logic modification, potentially leading to unauthorized directory access or authentication bypass. The vulnerability is resolved in version 2026.9.1 and later.

Affected products

  • Okta Access Gateway prior to 2026.9.1

Timeline

  • 2026-09-08: disclosed
  • 2026-09-08: patched: Version 2026.9.1 and later contains fix

References

Related threats