Impact
The Okta Access Gateway fails to properly sanitize user input and evaluates regular expressions incorrectly within its Protected Rule authorization check, a weakness corresponding to CWE‑863. Based on the description, an attacker that can trigger the vulnerable logic can bypass authorization controls and gain access to application resources that administrators intended to protect, effectively elevating privileges within the gateway.
Affected Systems
All Okta Access Gateway installations that have administrators configuring Protected Rule policies on one or more application resources are affected. No specific minor versions are listed, so any deployment using the affected product with such policies carries the risk.
Risk and Exploitability
The CVSS score of 8.1 indicates high severity. The EPSS score is not available, so the exact likelihood of exploitation cannot be determined. The vulnerability is not listed in the CISA KEV catalog. The most probable attack vector involves crafting requests that exploit the improper input handling within the authorization logic; successful exploitation produces an authorization bypass rather than a full system compromise.
OpenCVE Enrichment