Description
The Okta Access Gateway does not apply its Lua directive restriction to the application-level custom configuration field. The field is interpolated directly into the nginx server block without inspection, resulting in execution of injected directives.
No analysis available yet.
Remediation
Vendor Solution
Upgrade the Okta Access Gateway appliance to version 2026.9.1 or greater.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Tue, 08 Sep 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Okta Access Gateway does not apply its Lua directive restriction to the application-level custom configuration field. The field is interpolated directly into the nginx server block without inspection, resulting in execution of injected directives. | |
| Title | Validation Bypass in Okta Access Gateway Custom Directives | |
| Weaknesses | CWE-693 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: Okta
Published:
Updated: 2026-09-08T20:08:58.455Z
Reserved: 2026-08-24T19:22:41.548Z
Link: CVE-2026-78552
No data.
Status : Awaiting Analysis
Published: 2026-09-08T20:18:36.073
Modified: 2026-09-08T21:13:32.293
Link: CVE-2026-78552
No data.
OpenCVE Enrichment
No data.
Weaknesses
-
CWE-693
Protection Mechanism Failure