Impact
An attacker who can create or modify dashboard application labels on the Okta Access Gateway can insert arbitrary PHP code into the generated configuration file. Because the file is automatically included during authentication requests, this code runs with the privileges of the web server process. The vulnerability is coded as CWE-94, indicating an injection of executable code. An exploit could give attackers full command execution on the host, resulting in compromise of confidentiality, integrity, and availability of the system. Based on the description, the likely attack vector is via a web-based interface that allows dashboard label modification.
Affected Systems
All installations of Okta Access Gateway that have not applied the recommended update to version 2026.9.1 or later are affected. The advisory specifically targets the dashboard site configuration feature within the product.
Risk and Exploitability
The CVSS score of 6.7 reflects moderate severity; no EPSS score is available and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is through the web application, where an authenticated user can create or modify dashboard labels. Once injected, the malicious code is executed during normal authentication flow, meaning the exploit does not require special network-level access. Based on the description, the risk is moderate, but the impact of code execution warrants immediate attention.
OpenCVE Enrichment