Impact
The Okta Access Gateway fails to sanitize the application label field before inserting it into the generated Nginx configuration file. An attacker who can supply a crafted application label can inject arbitrary Nginx directives, potentially leading to remote code execution, unauthorized configuration changes, or denial of service. The vulnerability is classified as an injection flaw (CWE-94).
Affected Systems
The vulnerability affects Okta Access Gateway appliances running versions prior to 2026.9.1. No specific build or minor release numbers are listed by the CNA; all deployments of the product before the release of 2026.9.1 are considered affected.
Risk and Exploitability
With a CVSS score of 6.6 the vulnerability is rated medium severity. The EPSS score is not available, and the vulnerability is not currently listed in the CISA KEV catalog, indicating no confirmed active exploitation. Exploitation requires the ability to add or modify an application label, which likely limits the attack surface to authenticated administrators or compromised user accounts with configuration rights. Once injected, the attacker can execute Nginx server block directives with the privileges of the Nginx process, potentially compromising the host.
OpenCVE Enrichment