Description
The Okta Access Gateway does not sanitize SAML assertion values before interpolating them into database queries in the advanced mode datastore configuration. The unsanitized values are substituted directly into the query string prior to preparation, resulting in unintended SQL execution against the configured backend database.
Published: 2026-09-08
Score: 7.7 High
EPSS: < 1% Very Low
KEV: No
Impact: SQL Injection leading to unauthorized database access
Action: Immediate Patch
AI Analysis

Impact

The Okta Access Gateway does not sanitize values extracted from SAML assertions before interpolating them into database queries when advanced mode datastore configuration is active. Unsanitized attributes are straightly inserted into the query string prior to preparation, enabling an attacker who can forge or manipulate a SAML assertion to influence the SQL command executed against the backend database. Based on the description, it is inferred that the flaw could lead to data leakage, data modification, or denial of service, depending on database privileges granted to the gateway process.

Affected Systems

The vulnerability affects the Okta Access Gateway appliance when deployed with the advanced mode datastore turned on. All instances of Okta Access Gateway prior to version 2026.9.1 are affected; the upgrade to 2026.9.1 or newer eliminates the flaw. No further sub-version details are specified beyond the cutoff date.

Risk and Exploitability

The advisory assigns a CVSS score of 7.7, indicating high severity. No EPSS score is currently available, so the popularity of exploitation remains unknown. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog, suggesting that no widespread active exploitation has been reported at the time of the advisory. Based on the description, it is inferred that a remote attacker would need to supply a crafted SAML assertion to the gateway, potentially bypassing tenant isolation and injecting arbitrary SQL into the datastore queries.

Generated by OpenCVE AI on September 9, 2026 at 10:27 UTC.

Remediation

Vendor Solution

Upgrade the Okta Access Gateway appliance to version 2026.9.1 or greater.


OpenCVE Recommended Actions

  • Upgrade the Okta Access Gateway appliance to version 2026.9.1 or later, which sanitizes SAML assertion attributes before query interpolation.
  • If an upgrade cannot be performed immediately, disable the advanced mode datastore configuration or restrict the gateway to only accept SAML assertions from trusted identity providers that have been verified to send safe attributes.
  • Monitor database logs for anomalous query patterns or error messages that may indicate injection attempts, and investigate any unexpected SAML attribute values detected during normal operation.

Generated by OpenCVE AI on September 9, 2026 at 10:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 22 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:okta:access_gateway:*:*:*:*:*:*:*:*

Sun, 13 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Okta
Okta access Gateway
Vendors & Products Okta
Okta access Gateway

Thu, 10 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description The Okta Access Gateway does not sanitize SAML assertion values before interpolating them into database queries in the advanced mode datastore configuration. The unsanitized values are substituted directly into the query string prior to preparation, resulting in unintended SQL execution against the configured backend database.
Title Improper Handling of SAML Assertion Attributes in Okta Access Gateway Advanced Mode Datastores
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 7.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:L/A:L'}


Subscriptions

Okta Access Gateway
cve-icon MITRE

Status: PUBLISHED

Assigner: Okta

Published:

Updated: 2026-09-10T17:52:13.925Z

Reserved: 2026-08-24T22:04:00.474Z

Link: CVE-2026-78623

cve-icon Vulnrichment

Updated: 2026-09-10T17:52:07.604Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T20:18:37.050

Modified: 2026-09-22T20:27:41.180

Link: CVE-2026-78623

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-13T20:07:16Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')