Impact
The Okta Access Gateway does not neutralize shell metacharacters in SNMP configuration values before a privileged script uses them to construct OS commands. An authenticated local user who can access the management interface can provide crafted values that cause the gateway to execute arbitrary OS commands with root privileges. This vulnerability enables a local attacker to take full control of the appliance by running arbitrary commands on the host system.
Affected Systems
Okta Access Gateway appliances running versions prior to 2026.9.1 are affected. No specific version range is provided in the advisory, so any version without the 2026.9.1 update should be considered vulnerable.
Risk and Exploitability
The CVSS score of 6.7 indicates a moderate severity. Since the EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, the likelihood of widespread exploitation is unclear. The attack requires local, authenticated access to the management interface, implying that an insider or a compromised local user can trigger the flaw. Once triggered, the attacker can execute arbitrary commands with root privileges, leading to a full compromise of the gateway appliance.
OpenCVE Enrichment