Description
The Okta Access Gateway does not sanitize dashboard label values before writing them into generated PHP configuration files. The generated file is automatically included during authentication requests, resulting in execution with the privileges of the web server process.
Published: 2026-09-08
Score: 6.7 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution via un-sanitized dashboard label injection
Action: Patch
AI Analysis

Impact

An attacker who can create or modify dashboard application labels on the Okta Access Gateway can insert arbitrary PHP code into the generated configuration file. Because the file is automatically included during authentication requests, this code runs with the privileges of the web server process. The vulnerability is coded as CWE-94, indicating an injection of executable code. An exploit could give attackers full command execution on the host, resulting in compromise of confidentiality, integrity, and availability of the system. Based on the description, the likely attack vector is via a web-based interface that allows dashboard label modification.

Affected Systems

All installations of Okta Access Gateway that have not applied the recommended update to version 2026.9.1 or later are affected. The advisory specifically targets the dashboard site configuration feature within the product.

Risk and Exploitability

The CVSS score of 6.7 reflects moderate severity; no EPSS score is available and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is through the web application, where an authenticated user can create or modify dashboard labels. Once injected, the malicious code is executed during normal authentication flow, meaning the exploit does not require special network-level access. Based on the description, the risk is moderate, but the impact of code execution warrants immediate attention.

Generated by OpenCVE AI on September 9, 2026 at 10:25 UTC.

Remediation

Vendor Solution

Upgrade Okta Access Gateway to version 2026.9.1 or greater.


OpenCVE Recommended Actions

  • Upgrade Okta Access Gateway to version 2026.9.1 or later to apply the vendor‑supplied fix.
  • If an upgrade is not immediately possible, restrict dashboard label values to safe characters (e.g., alphanumerics) and enforce server‑side validation to prevent PHP code injection.
  • Disable or modify the mechanism that automatically includes dynamically generated configuration files during authentication to prevent unintended code execution.

Generated by OpenCVE AI on September 9, 2026 at 10:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 22 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:okta:access_gateway:*:*:*:*:*:*:*:*

Sun, 13 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Okta
Okta access Gateway
Vendors & Products Okta
Okta access Gateway

Thu, 10 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description The Okta Access Gateway does not sanitize dashboard label values before writing them into generated PHP configuration files. The generated file is automatically included during authentication requests, resulting in execution with the privileges of the web server process.
Title Insufficient Validation of Dashboard Application Labels in Okta Access Gateway Dashboard Site Configuration
Weaknesses CWE-94
References
Metrics cvssV3_1

{'score': 6.7, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Okta Access Gateway
cve-icon MITRE

Status: PUBLISHED

Assigner: Okta

Published:

Updated: 2026-09-10T14:34:56.113Z

Reserved: 2026-08-24T22:04:00.475Z

Link: CVE-2026-78625

cve-icon Vulnrichment

Updated: 2026-09-10T14:34:52.039Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T20:18:37.647

Modified: 2026-09-22T20:16:41.267

Link: CVE-2026-78625

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-13T20:07:04Z

Weaknesses
  • CWE-94

    Improper Control of Generation of Code ('Code Injection')