Impact
The vulnerability in Okta Access Gateway’s Kerberos configuration handler allows an attacker to specify arbitrary file paths in event payloads, which the system then writes to directly without validation. This flaw permits a malicious party to create or overwrite files in unintended locations on the appliance filesystem, potentially compromising system integrity or confidentiality. The weakness corresponds to CWE-73: Improper Validation of File Path.
Affected Systems
All Okta Access Gateway appliances are affected, regardless of version, until an upgrade to version 2026.9.1 or later is applied. The vendor’s advisory recommends moving to the 2026.9.1 release or newer to mitigate the issue.
Risk and Exploitability
The CVSS score of 5.9 indicates a medium severity vulnerability. Because the attack hinges on the ability to submit crafted event payloads, the exploit is likely possible remotely if the gateway accepts externally supplied events. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting that it may not yet be actively exploited in the wild. Nonetheless, the potential for file overwrite warrants prompt action.
OpenCVE Enrichment