Impact
The vulnerability occurs when the Okta Access Gateway’s pass‑through authentication source accepts a client‑supplied HTTP header that identifies a user without performing cryptographic validation. Because the header is unsanitized, an attacker can set the value to any username, enabling a party that is otherwise unauthenticated to initiate a session. This flaw maps to CWE‑287 and effectively provides the ability to hijack or spoof a user’s identity, raising confidentiality and integrity risks by allowing unauthenticated users to impersonate any account.
Affected Systems
The flaw affects installations of the Okta Access Gateway when the optional pass‑through authentication source feature is configured. No specific version constraints are provided beyond the need to upgrade to the recommended 2026.9.1 baseline. The risk applies regardless of the gateway’s operating environment, provided an upstream reverse proxy or firewall has not already been enforcing header integrity.
Risk and Exploitability
The listed CVSS score of 4.8 reflects moderate severity, and the EPSS value is not available. Since the vulnerability can be exploited by sending a crafted HTTP header directly to the gateway, the attack vector is likely remote over the network unless the gateway is isolated. Because it is not currently listed in the CISA KEV catalog, no publicly known exploits have been reported, but the ease of construction of a malicious header means the risk remains significant in scenarios where sanitization is missing.
OpenCVE Enrichment