Impact
The Okta Access Gateway backup restore function fails to validate a filename that is embedded in an encrypted backup payload, allowing an attacker to cause the appliance to write file contents to locations other than intended. If a malicious payload is successfully restored, the content could overwrite critical configuration files or deploy unauthorized binaries, compromising the integrity and availability of the gateway and potentially exposing sensitive data.
Affected Systems
Okta Access Gateway appliances running versions prior to 2026.9.1 are affected. Upgrading to version 2026.9.1 or later resolves the path validation flaw.
Risk and Exploitability
The CVSS score is 4.9, indicating moderate risk. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, so current evidence of exploitation is limited. The likely attack vector is an authorized or potentially compromised user delegating the installation of a backup payload; the function accepts backups, so an attacker who can supply a crafted backup file would have the prerequisites to exploit the weakness.
OpenCVE Enrichment