Junglewise Threat Intelligence

CVE-2026-78624: Okta Access Gateway path traversal in backup restore

CVE-2026-78624 · Severity: medium · CVSS 4.9 · Published 2026-09-08

Technologies: Okta Access Gateway. Vendors: Okta.

Executive brief

The Okta Access Gateway is a network appliance used to manage secure access to enterprise applications. A vulnerability in the backup restore function allows authenticated administrators to write files to arbitrary locations on the appliance filesystem, potentially compromising system integrity or confidentiality.

Technical details

The vulnerability is a path traversal (CWE-22) in the Okta Access Gateway backup restore function. The backup restore mechanism does not properly validate the filename embedded within encrypted backup payloads, allowing an attacker to specify paths with directory traversal sequences (e.g., "../../../") to write files outside the intended directory. Exploitation requires network access to the administrative management interface and authenticated administrator privileges with authorization to upload and restore backup files. An attacker can achieve arbitrary file write with the privileges of the appliance process, potentially exposing sensitive configuration data or modifying system files. The vulnerability is patched in version 2026.9.1 and later.

Affected products

  • Okta Access Gateway prior to 2026.9.1

Timeline

  • 2026-09-08: disclosed
  • 2026-09-01: patched: Fix available in version 2026.9.1

References

Related threats