Description
The Okta Access Gateway backup restore function does not validate the filename embedded in an encrypted backup payload. This results in writing file contents to unintended locations on the appliance filesystem.
Published: 2026-09-08
Score: 4.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Write to unintended file locations on the appliance filesystem
Action: Apply Patch
AI Analysis

Impact

The Okta Access Gateway backup restore function fails to validate a filename that is embedded in an encrypted backup payload, allowing an attacker to cause the appliance to write file contents to locations other than intended. If a malicious payload is successfully restored, the content could overwrite critical configuration files or deploy unauthorized binaries, compromising the integrity and availability of the gateway and potentially exposing sensitive data.

Affected Systems

Okta Access Gateway appliances running versions prior to 2026.9.1 are affected. Upgrading to version 2026.9.1 or later resolves the path validation flaw.

Risk and Exploitability

The CVSS score is 4.9, indicating moderate risk. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, so current evidence of exploitation is limited. The likely attack vector is an authorized or potentially compromised user delegating the installation of a backup payload; the function accepts backups, so an attacker who can supply a crafted backup file would have the prerequisites to exploit the weakness.

Generated by OpenCVE AI on September 9, 2026 at 09:29 UTC.

Remediation

Vendor Solution

Upgrade the Okta Access Gateway appliance to version 2026.9.1 or greater.


OpenCVE Recommended Actions

  • Upgrade the Okta Access Gateway appliance to version 2026.9.1 or later
  • Limit the acceptance of backup files to trusted administrators only
  • Validate and sanitize filenames used in backup restore operations to prevent unintended file writes

Generated by OpenCVE AI on September 9, 2026 at 09:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 22 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:okta:access_gateway:*:*:*:*:*:*:*:*

Sun, 13 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Okta
Okta access Gateway
Vendors & Products Okta
Okta access Gateway

Thu, 10 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description The Okta Access Gateway backup restore function does not validate the filename embedded in an encrypted backup payload. This results in writing file contents to unintended locations on the appliance filesystem.
Title Improper Path Validation in Okta Access Gateway Backup and Restore Functionality
Weaknesses CWE-22
References
Metrics cvssV3_1

{'score': 4.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Okta Access Gateway
cve-icon MITRE

Status: PUBLISHED

Assigner: Okta

Published:

Updated: 2026-09-10T14:31:46.246Z

Reserved: 2026-08-24T22:04:00.475Z

Link: CVE-2026-78624

cve-icon Vulnrichment

Updated: 2026-09-10T14:31:40.220Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T20:18:37.397

Modified: 2026-09-22T20:19:15.390

Link: CVE-2026-78624

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-13T20:07:06Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')