Description
The Okta Access Gateway improperly handles input sanitization and regular expression evaluation within its Protected Rule authorization check, resulting in an authorization bypass when an administrator has explicitly configured a Protected Rule policy on one or more application resources.
Published: 2026-09-08
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Authorization Bypass
Action: Patch Now
AI Analysis

Impact

The Okta Access Gateway fails to properly sanitize user input and evaluates regular expressions incorrectly within its Protected Rule authorization check, a weakness corresponding to CWE‑863. Based on the description, an attacker that can trigger the vulnerable logic can bypass authorization controls and gain access to application resources that administrators intended to protect, effectively elevating privileges within the gateway.

Affected Systems

All Okta Access Gateway installations that have administrators configuring Protected Rule policies on one or more application resources are affected. No specific minor versions are listed, so any deployment using the affected product with such policies carries the risk.

Risk and Exploitability

The CVSS score of 8.1 indicates high severity. The EPSS score is not available, so the exact likelihood of exploitation cannot be determined. The vulnerability is not listed in the CISA KEV catalog. The most probable attack vector involves crafting requests that exploit the improper input handling within the authorization logic; successful exploitation produces an authorization bypass rather than a full system compromise.

Generated by OpenCVE AI on September 9, 2026 at 11:50 UTC.

Remediation

Vendor Solution

Upgrade Okta Access Gateway to version 2026.9.1 or greater.


OpenCVE Recommended Actions

  • Upgrade Okta Access Gateway to version 2026.9.1 or newer, as recommended by Okta.
  • Verify that all administrative accounts no longer rely on legacy Protected Rule policy configurations; reconfigure policies if necessary to eliminate the flaw.
  • Limit the number of administrators who can create or modify Protected Rule policies and monitor those accounts for suspicious activity.

Generated by OpenCVE AI on September 9, 2026 at 11:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 22 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:okta:access_gateway:*:*:*:*:*:*:*:*

Sun, 13 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Okta
Okta access Gateway
Vendors & Products Okta
Okta access Gateway

Thu, 10 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description The Okta Access Gateway improperly handles input sanitization and regular expression evaluation within its Protected Rule authorization check, resulting in an authorization bypass when an administrator has explicitly configured a Protected Rule policy on one or more application resources.
Title Improper Input Sanitization in Okta Access Gateway Protected Rules
Weaknesses CWE-863
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

Okta Access Gateway
cve-icon MITRE

Status: PUBLISHED

Assigner: Okta

Published:

Updated: 2026-09-10T14:35:50.946Z

Reserved: 2026-08-24T22:04:00.475Z

Link: CVE-2026-78626

cve-icon Vulnrichment

Updated: 2026-09-10T14:35:46.219Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T20:18:38.070

Modified: 2026-09-22T20:14:53.140

Link: CVE-2026-78626

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-13T20:07:02Z

Weaknesses