Executive brief
Okta Access Gateway is an identity and access management appliance used to secure network access. An authenticated local user with SSH management access can inject shell metacharacters into SNMP configuration settings, allowing arbitrary OS commands to execute with root privileges. This could enable an attacker with valid management credentials to fully compromise the appliance and the systems it protects.
Technical details
The vulnerability is an OS command injection (CWE-78) in the SNMP configuration processing of Okta Access Gateway. The appliance fails to sanitize shell metacharacters in SNMP configuration values before passing them to a privileged script that constructs and executes OS commands. An authenticated user with access to the SSH management interface and valid management credentials can navigate to the SNMP configuration menu and supply crafted values containing shell metacharacters to trigger arbitrary command execution with root privileges. The attack requires local network access to the management interface, valid management account credentials, and user interaction to access the configuration menu. This vulnerability is fixed in version 2026.9.1 and later.
Affected products
- Okta Access Gateway prior to 2026.9.1
Timeline
- 2026-09-08: disclosed