Impact
The Okta Access Gateway fails to sanitize SAML assertion attribute values before using them in LDAP search filters configured for the LDAP datastore. The unsanitized values are directly interpolated into the filter string and passed to the LDAP search operation, which can alter the intended query logic. This flaw permits an attacker to craft a SAML assertion that modifies the LDAP filter, potentially allowing arbitrary queries or manipulation of the search results.
Affected Systems
The vulnerability affects the Okta Access Gateway appliance from Okta. All releases prior to version 2026.9.1 are susceptible. Any environment that relies on Okta Access Gateway for SAML assertion processing and LDAP datastore configuration is at risk.
Risk and Exploitability
The CVSS score of 6.8 indicates moderate severity. EPSS information is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting no confirmed exploitation in the wild. However, the flaw is exploitable remotely by sending crafted SAML assertions that are processed by the gateway. Because the issue originates from input handling, a threat actor who can influence SAML assertions can modify LDAP queries, potentially extracting sensitive directory information or bypassing expected filtering logic.
OpenCVE Enrichment