Description
The Okta Access Gateway does not sanitize the application label field before including it in the generated nginx configuration file. The unsanitized value is interpolated into an nginx server block directive, resulting in execution of injected directives.
Published: 2026-09-08
Score: 6.6 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Remote code execution via Nginx configuration injection
Action: Patch
AI Analysis

Impact

The Okta Access Gateway fails to sanitize the application label field before inserting it into the generated Nginx configuration file. An attacker who can supply a crafted application label can inject arbitrary Nginx directives, potentially leading to remote code execution, unauthorized configuration changes, or denial of service. The vulnerability is classified as an injection flaw (CWE-94).

Affected Systems

The vulnerability affects Okta Access Gateway appliances running versions prior to 2026.9.1. No specific build or minor release numbers are listed by the CNA; all deployments of the product before the release of 2026.9.1 are considered affected.

Risk and Exploitability

With a CVSS score of 6.6 the vulnerability is rated medium severity. The EPSS score is not available, and the vulnerability is not currently listed in the CISA KEV catalog, indicating no confirmed active exploitation. Exploitation requires the ability to add or modify an application label, which likely limits the attack surface to authenticated administrators or compromised user accounts with configuration rights. Once injected, the attacker can execute Nginx server block directives with the privileges of the Nginx process, potentially compromising the host.

Generated by OpenCVE AI on September 9, 2026 at 10:28 UTC.

Remediation

Vendor Solution

Upgrade the Okta Access Gateway appliance to version 2026.9.1 or greater.


OpenCVE Recommended Actions

  • Upgrade the Okta Access Gateway appliance to version 2026.9.1 or newer, as released by the vendor.
  • Restrict permission to modify application labels so that only privileged administrators can change them, reducing the number of accounts that could supply malicious input.
  • Implement input validation or sanitization on the application label field to allow only safe characters or patterns, preventing injection of unintended Nginx directives.

Generated by OpenCVE AI on September 9, 2026 at 10:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 13 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Okta
Okta access Gateway
Vendors & Products Okta
Okta access Gateway

Thu, 10 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description The Okta Access Gateway does not sanitize the application label field before including it in the generated nginx configuration file. The unsanitized value is interpolated into an nginx server block directive, resulting in execution of injected directives.
Title Improper Input Sanitization in Okta Access Gateway Application Label Configuration
Weaknesses CWE-94
References
Metrics cvssV3_1

{'score': 6.6, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Okta Access Gateway
cve-icon MITRE

Status: PUBLISHED

Assigner: Okta

Published:

Updated: 2026-09-10T18:01:32.244Z

Reserved: 2026-08-24T18:44:02.108Z

Link: CVE-2026-78545

cve-icon Vulnrichment

Updated: 2026-09-10T18:00:49.415Z

cve-icon NVD

Status : Undergoing Analysis

Published: 2026-09-08T20:18:35.727

Modified: 2026-09-10T19:17:34.710

Link: CVE-2026-78545

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-13T20:07:21Z

Weaknesses
  • CWE-94

    Improper Control of Generation of Code ('Code Injection')