Executive brief
Okta Access Gateway is a secure appliance used to authenticate users to on-premises applications via Kerberos. A vulnerability in its Kerberos configuration handler allows authenticated administrators or local attackers to write files to arbitrary locations on the appliance filesystem, potentially compromising system integrity and enabling further attacks on the infrastructure it protects.
Technical details
The vulnerability is an arbitrary file write (CWE-73) in the Kerberos configuration handler. The handler accepts file paths from event payloads without validation, using them directly as write destinations. This allows an attacker with authenticated administrative network access or local access to the event pipeline directory (/opt/oag/events) to write malicious files to unintended filesystem locations. An attacker could overwrite critical appliance configuration files, inject malicious code, or establish persistence. The vulnerability is resolved in Okta Access Gateway version 2026.9.1 and later.
Affected products
- Okta Access Gateway prior to 2026.9.1
Timeline
- 2026-09-08: disclosed