Executive brief
Okta Access Gateway is a critical identity access management component that enforces authorization policies on application resources. A flaw in how it validates user permissions against Protected Rules allows authenticated users to bypass access restrictions they should not have, potentially granting unauthorized access to sensitive applications and data.
Technical details
The vulnerability is an authorization bypass (CWE-863) caused by improper input sanitization and insecure regular expression evaluation in the Protected Rule authorization check. The attack requires an authenticated user with a valid account assigned to the protected application, and affects deployments where administrators have explicitly configured Protected Rule policies. An attacker can craft malicious input to circumvent the authorization checks and gain access to protected resources. The issue is fixed in version 2026.9.1 and later; all earlier versions are vulnerable.
Affected products
- Okta Access Gateway prior to 2026.9.1
Timeline
- 2026-09-08: disclosed