Description
The Okta Access Gateway does not neutralize shell metacharacters in SNMP configuration values before a privileged script uses them to construct OS commands. An authenticated local user with access to the management interface can supply crafted values, resulting in the execution of arbitrary OS commands with root privileges.
Published: 2026-09-08
Score: 6.7 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Command Execution and Privilege Escalation
Action: Immediate Patch
AI Analysis

Impact

The Okta Access Gateway does not neutralize shell metacharacters in SNMP configuration values before a privileged script uses them to construct OS commands. An authenticated local user who can access the management interface can provide crafted values that cause the gateway to execute arbitrary OS commands with root privileges. This vulnerability enables a local attacker to take full control of the appliance by running arbitrary commands on the host system.

Affected Systems

Okta Access Gateway appliances running versions prior to 2026.9.1 are affected. No specific version range is provided in the advisory, so any version without the 2026.9.1 update should be considered vulnerable.

Risk and Exploitability

The CVSS score of 6.7 indicates a moderate severity. Since the EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, the likelihood of widespread exploitation is unclear. The attack requires local, authenticated access to the management interface, implying that an insider or a compromised local user can trigger the flaw. Once triggered, the attacker can execute arbitrary commands with root privileges, leading to a full compromise of the gateway appliance.

Generated by OpenCVE AI on September 9, 2026 at 09:23 UTC.

Remediation

Vendor Solution

Upgrade the Okta Access Gateway appliance to version 2026.9.1 or greater.


OpenCVE Recommended Actions

  • Upgrade the gateway to version 2026.9.1 or later, which neutralizes SNMP input.
  • If an immediate upgrade is not possible, disable SNMP configuration processing or remove SNMP functionality from the appliance.
  • Limit access to the management interface to trusted administrators only, using firewall rules or VPN restrictions to prevent unauthorized local access.

Generated by OpenCVE AI on September 9, 2026 at 09:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 22 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:okta:access_gateway:*:*:*:*:*:*:*:*

Sun, 13 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Okta
Okta access Gateway
Vendors & Products Okta
Okta access Gateway

Thu, 10 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Description The Okta Access Gateway does not neutralize shell metacharacters in SNMP configuration values before a privileged script uses them to construct OS commands. An authenticated local user with access to the management interface can supply crafted values, resulting in the execution of arbitrary OS commands with root privileges.
Title Improper Input Neutralization in Okta Access Gateway SNMP Configuration Processing
Weaknesses CWE-78
References
Metrics cvssV3_1

{'score': 6.7, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Okta Access Gateway
cve-icon MITRE

Status: PUBLISHED

Assigner: Okta

Published:

Updated: 2026-09-10T14:40:54.476Z

Reserved: 2026-08-24T22:04:00.475Z

Link: CVE-2026-78630

cve-icon Vulnrichment

Updated: 2026-09-10T14:40:16.378Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T21:18:41.457

Modified: 2026-09-22T20:02:52.180

Link: CVE-2026-78630

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-13T20:06:48Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')