Impact
The vulnerability in Okta Access Gateway is a validation bypass that allows malicious content to be injected into the Nginx server block. Because the gateway does not enforce Lua directive restrictions on the application–level custom configuration field, an attacker can craft arbitrary Nginx directives that are interpolated and executed without inspection. This flaw is an example of improper validation or sanitization (CWE‑693) and gives the attacker the ability to run code, modify host configuration, and compromise the confidentiality, integrity, and availability of services protected by the gateway.
Affected Systems
Okta Access Gateway appliances running any version earlier than 2026.9.1 are vulnerable, as the fix applies only to appliances upgraded to 2026.9.1 or later.
Risk and Exploitability
The CVSS score of 6 indicates moderate severity, and the EPC score is not available with no evidence that it has been listed in CISA’s KEV catalog. Attack vectors are likely limited to users who have permission to alter the gateway’s custom configuration, such as administrators or privileged users. Upon successful injection, the extraneous Nginx directives are executed with the privileges of the gateway host, providing remote code execution potential.
OpenCVE Enrichment