Description
The Okta Access Gateway does not sanitize SAML assertion attribute values before interpolating them into LDAP search filters in the LDAP datastore configuration. The raw values are substituted directly into the filter string and passed to the LDAP search operation, resulting in modification of the intended query logic.
Published: 2026-09-08
Score: 6.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: LDAP Injection leading to unauthorized data access
Action: Apply Patch
AI Analysis

Impact

The Okta Access Gateway fails to sanitize SAML assertion attribute values before using them in LDAP search filters configured for the LDAP datastore. The unsanitized values are directly interpolated into the filter string and passed to the LDAP search operation, which can alter the intended query logic. This flaw permits an attacker to craft a SAML assertion that modifies the LDAP filter, potentially allowing arbitrary queries or manipulation of the search results.

Affected Systems

The vulnerability affects the Okta Access Gateway appliance from Okta. All releases prior to version 2026.9.1 are susceptible. Any environment that relies on Okta Access Gateway for SAML assertion processing and LDAP datastore configuration is at risk.

Risk and Exploitability

The CVSS score of 6.8 indicates moderate severity. EPSS information is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting no confirmed exploitation in the wild. However, the flaw is exploitable remotely by sending crafted SAML assertions that are processed by the gateway. Because the issue originates from input handling, a threat actor who can influence SAML assertions can modify LDAP queries, potentially extracting sensitive directory information or bypassing expected filtering logic.

Generated by OpenCVE AI on September 9, 2026 at 09:26 UTC.

Remediation

Vendor Solution

Upgrade the Okta Access Gateway appliance to version 2026.9.1 or greater.


OpenCVE Recommended Actions

  • Upgrade the Okta Access Gateway appliance to version 2026.9.1 or newer.
  • If an upgrade cannot be performed immediately, restrict or validate the attribute values permitted in SAML assertions to prevent injection into LDAP filters.
  • Monitor LDAP query logs for abnormal patterns that may indicate attempts to exploit the injection flaw.

Generated by OpenCVE AI on September 9, 2026 at 09:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 23 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:okta:access_gateway:*:*:*:*:*:*:*:*

Sun, 13 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Okta
Okta access Gateway
Vendors & Products Okta
Okta access Gateway

Thu, 10 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description The Okta Access Gateway does not sanitize SAML assertion attribute values before interpolating them into LDAP search filters in the LDAP datastore configuration. The raw values are substituted directly into the filter string and passed to the LDAP search operation, resulting in modification of the intended query logic.
Title Improper Input Sanitization in Okta Access Gateway LDAP Datastore Filter Interpolation
Weaknesses CWE-90
References
Metrics cvssV3_1

{'score': 6.8, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

Okta Access Gateway
cve-icon MITRE

Status: PUBLISHED

Assigner: Okta

Published:

Updated: 2026-09-10T14:37:56.057Z

Reserved: 2026-08-24T20:50:31.443Z

Link: CVE-2026-78579

cve-icon Vulnrichment

Updated: 2026-09-10T14:37:50.856Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T20:18:36.590

Modified: 2026-09-23T18:17:08.527

Link: CVE-2026-78579

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-13T20:06:54Z

Weaknesses
  • CWE-90

    Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection')