Impact
The vulnerability arises when the Okta Access Gateway management console accepts user‑supplied data and passes it directly to eval() during an authenticated administrator SSH session. This unsanitized input is executed as code with the privileges of the console, allowing an attacker who can input data to run arbitrary code on the appliance. The primary impact is unrestricted code execution with console‑level authority.
Affected Systems
Okta Access Gateway appliances. The affected version range is not specified in the CNA data, but the fix is to upgrade to version 2026.9.1 or later.
Risk and Exploitability
The CVSS score of 6.6 categorises the vulnerability as a moderate severity. The EPSS score is not published, and the issue is not listed in the CISA KEV catalog, suggesting the exploitation likelihood is not currently high. The attack requires an authenticated administrator with SSH access, meaning the window of opportunity is limited to privileged users. Nonetheless, once an admin can inject malicious payloads, the appliance can be fully compromised.
OpenCVE Enrichment