Impact
The Okta Access Gateway does not sanitize values extracted from SAML assertions before interpolating them into database queries when advanced mode datastore configuration is active. Unsanitized attributes are straightly inserted into the query string prior to preparation, enabling an attacker who can forge or manipulate a SAML assertion to influence the SQL command executed against the backend database. Based on the description, it is inferred that the flaw could lead to data leakage, data modification, or denial of service, depending on database privileges granted to the gateway process.
Affected Systems
The vulnerability affects the Okta Access Gateway appliance when deployed with the advanced mode datastore turned on. All instances of Okta Access Gateway prior to version 2026.9.1 are affected; the upgrade to 2026.9.1 or newer eliminates the flaw. No further sub-version details are specified beyond the cutoff date.
Risk and Exploitability
The advisory assigns a CVSS score of 7.7, indicating high severity. No EPSS score is currently available, so the popularity of exploitation remains unknown. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog, suggesting that no widespread active exploitation has been reported at the time of the advisory. Based on the description, it is inferred that a remote attacker would need to supply a crafted SAML assertion to the gateway, potentially bypassing tenant isolation and injecting arbitrary SQL into the datastore queries.
OpenCVE Enrichment