Description
The Okta Access Gateway includes an optional pass-through authentication source that accepts user identity from a client-supplied HTTP header without cryptographic validation. In architectures where this optional source is enabled without an upstream reverse proxy or firewall configured to sanitize and enforce client headers, an unauthenticated user can supply an arbitrary identity value to initiate a session.
Published: 2026-09-08
Score: 4.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Authentication Bypass
Action: Patch
AI Analysis

Impact

The vulnerability occurs when the Okta Access Gateway’s pass‑through authentication source accepts a client‑supplied HTTP header that identifies a user without performing cryptographic validation. Because the header is unsanitized, an attacker can set the value to any username, enabling a party that is otherwise unauthenticated to initiate a session. This flaw maps to CWE‑287 and effectively provides the ability to hijack or spoof a user’s identity, raising confidentiality and integrity risks by allowing unauthenticated users to impersonate any account.

Affected Systems

The flaw affects installations of the Okta Access Gateway when the optional pass‑through authentication source feature is configured. No specific version constraints are provided beyond the need to upgrade to the recommended 2026.9.1 baseline. The risk applies regardless of the gateway’s operating environment, provided an upstream reverse proxy or firewall has not already been enforcing header integrity.

Risk and Exploitability

The listed CVSS score of 4.8 reflects moderate severity, and the EPSS value is not available. Since the vulnerability can be exploited by sending a crafted HTTP header directly to the gateway, the attack vector is likely remote over the network unless the gateway is isolated. Because it is not currently listed in the CISA KEV catalog, no publicly known exploits have been reported, but the ease of construction of a malicious header means the risk remains significant in scenarios where sanitization is missing.

Generated by OpenCVE AI on September 9, 2026 at 09:30 UTC.

Remediation

Vendor Solution

Upgrade the Okta Access Gateway appliance to version 2026.9.1 or greater.


OpenCVE Recommended Actions

  • Upgrade the Okta Access Gateway appliance to version 2026.9.1 or later.
  • If the pass‑through authentication source is not required, disable that feature in the gateway configuration.
  • Ensure that any upstream reverse proxy or firewall sanitizes and enforces client headers, rejecting or rejecting arbitrary identity values before they reach the gateway.

Generated by OpenCVE AI on September 9, 2026 at 09:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 23 Sep 2026 18:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:okta:access_gateway:*:*:*:*:*:*:*:*

Sun, 13 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Okta
Okta access Gateway
Vendors & Products Okta
Okta access Gateway

Thu, 10 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description The Okta Access Gateway includes an optional pass-through authentication source that accepts user identity from a client-supplied HTTP header without cryptographic validation. In architectures where this optional source is enabled without an upstream reverse proxy or firewall configured to sanitize and enforce client headers, an unauthenticated user can supply an arbitrary identity value to initiate a session.
Title Improper Authentication Validation in Okta Access Gateway Pass-Through Authentication Source
Weaknesses CWE-287
References
Metrics cvssV3_1

{'score': 4.8, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N'}


Subscriptions

Okta Access Gateway
cve-icon MITRE

Status: PUBLISHED

Assigner: Okta

Published:

Updated: 2026-09-10T14:30:58.493Z

Reserved: 2026-08-24T20:01:42.878Z

Link: CVE-2026-78560

cve-icon Vulnrichment

Updated: 2026-09-10T14:30:53.542Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T20:18:36.220

Modified: 2026-09-23T18:00:37.843

Link: CVE-2026-78560

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-13T20:07:08Z

Weaknesses