Description
The Okta Access Gateway management console passes user-supplied input to eval() without sanitization during an authenticated administrator SSH session. As a result, the unsanitized input is executed directly, leading to code execution with the privileges of the management console.
Published: 2026-09-08
Score: 6.6 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The vulnerability arises when the Okta Access Gateway management console accepts user‑supplied data and passes it directly to eval() during an authenticated administrator SSH session. This unsanitized input is executed as code with the privileges of the console, allowing an attacker who can input data to run arbitrary code on the appliance. The primary impact is unrestricted code execution with console‑level authority.

Affected Systems

Okta Access Gateway appliances. The affected version range is not specified in the CNA data, but the fix is to upgrade to version 2026.9.1 or later.

Risk and Exploitability

The CVSS score of 6.6 categorises the vulnerability as a moderate severity. The EPSS score is not published, and the issue is not listed in the CISA KEV catalog, suggesting the exploitation likelihood is not currently high. The attack requires an authenticated administrator with SSH access, meaning the window of opportunity is limited to privileged users. Nonetheless, once an admin can inject malicious payloads, the appliance can be fully compromised.

Generated by OpenCVE AI on September 9, 2026 at 09:35 UTC.

Remediation

Vendor Solution

Upgrade the Okta Access Gateway appliance to version 2026.9.1 or greater.


OpenCVE Recommended Actions

  • Upgrade the Okta Access Gateway appliance to version 2026.9.1 or newer to apply the vendor patch.
  • Limit SSH access to the management console to only essential administrators and enforce two‑factor authentication.
  • Remove or refactor any eval usage in the management console code to eliminate unsafe runtime execution pathways.
  • Apply network segmentation or firewall rules to restrict external exposure of the management console services.

Generated by OpenCVE AI on September 9, 2026 at 09:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 13 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Okta
Okta access Gateway
Vendors & Products Okta
Okta access Gateway

Thu, 10 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description The Okta Access Gateway management console passes user-supplied input to eval() without sanitization during an authenticated administrator SSH session. As a result, the unsanitized input is executed directly, leading to code execution with the privileges of the management console.
Title Improper Input Handling in Okta Access Gateway Management Console Exception Handler
Weaknesses CWE-95
References
Metrics cvssV3_1

{'score': 6.6, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Okta Access Gateway
cve-icon MITRE

Status: PUBLISHED

Assigner: Okta

Published:

Updated: 2026-09-10T17:52:48.219Z

Reserved: 2026-08-24T19:02:48.517Z

Link: CVE-2026-78550

cve-icon Vulnrichment

Updated: 2026-09-10T17:52:42.507Z

cve-icon NVD

Status : Undergoing Analysis

Published: 2026-09-08T20:18:35.937

Modified: 2026-09-10T18:18:08.090

Link: CVE-2026-78550

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-13T20:07:19Z

Weaknesses
  • CWE-95

    Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')