Okta security advisories
View latest advisories
- Local Privilege Escalation in Auth0 AD/LDAP Connector CVE-2026-85983 - Sep 8, 2026
- Stored Cross-Site Scripting (XSS) in Auth0 AD/LDAP Connector CVE-2026-85982 - Sep 8, 2026
- Unauthenticated Localhost Admin Panel in Auth0 AD/LDAP Connector CVE-2026-85981 - Sep 8, 2026
- Improper Cache Isolation in auth0/react-native-auth0 SDK Web Platform Credential Management CVE-2026-84685 - Sep 8, 2026
- Improper Assembly Resolution in Okta Hyperdrive Integration Plugin Registry Handling CVE-2026-78574 - Sep 8, 2026
- Improper Input Sanitization in Okta Access Gateway Protected Rules CVE-2026-78626 - Sep 8, 2026
- Improper Credential Protection in Okta Hyperdrive Integration Installer Logging CVE-2026-78627 - Sep 8, 2026
- Improper Input Sanitization in Okta Access Gateway LDAP Datastore Filter Interpolation CVE-2026-78579 - Sep 8, 2026
- Improper Path Validation in Okta Access Gateway Kerberos Configuration Handling CVE-2026-78620 - Sep 8, 2026
- Improper Input Validation in the Okta Privileged Access SSH Client URL Handler Argument CVE-2026-78635 - Sep 8, 2026
- Improper Authentication Verification in the Okta Hyperdrive Agent MFA Response Handling CVE-2026-78629 - Sep 8, 2026
- Improper Input Neutralization in Okta Access Gateway SNMP Configuration Processing CVE-2026-78630 - Sep 8, 2026
- Improper Restriction of Sensitive Information in Okta Hyperdrive Agent Logging CVE-2026-78631 - Sep 8, 2026
- Improper Link Resolution in Okta Verify for Windows Uninstaller Data Removal CVE-2026-78622 - Sep 8, 2026
- Improper Input Sanitization in Okta Access Gateway Application Label Configuration CVE-2026-78545 - Sep 8, 2026
- Improper Input Handling in Okta Access Gateway Management Console Exception Handler CVE-2026-78550 - Sep 8, 2026
- Improper Handling of SAML Assertion Attributes in Okta Access Gateway Advanced Mode Datastores CVE-2026-78623 - Sep 8, 2026
- Validation Bypass in Okta Access Gateway Custom Directives CVE-2026-78552 - Sep 8, 2026
- Improper Authentication Validation in Okta Access Gateway Pass-Through Authentication Source CVE-2026-78560 - Sep 8, 2026
- Improper Path Validation in Okta Access Gateway Backup and Restore Functionality CVE-2026-78624 - Sep 8, 2026
- Insufficient Validation of Dashboard Application Labels in Okta Access Gateway Dashboard Site Configuration CVE-2026-78625 - Sep 8, 2026
- Improper Validation of SSH Target in Okta Privileged Access Client CVE-2026-77585 - Aug 25, 2026
- Bearer Token Accepted via URL Query Parameter in Auth0 Symfony SDK CVE-2026-50157 - Jun 10, 2026
- Improper Permission Checking in Auth0.js SDK CVE-2026-42280 - May 6, 2026
- Improper Proxy Cache Lookup in the Auth0 Next.js SDK CVE-2026-40155 - Apr 17, 2026
- Insufficient Entropy in Cookie Encryption in Auth0 Symfony SDK CVE-2026-34236 - Apr 1, 2026
- Insufficient Entropy in Cookie Encryption in Auth0 WordPress Plugin CVE-2026-34236 - Apr 1, 2026
- Insufficient Entropy in Cookie Encryption in Auth0 laravel-auth0 SDK CVE-2026-34236 - Apr 1, 2026
- Auth0 PHP SDK Insufficient Entropy in Cookie Encryption CVE-2026-34236 - Apr 1, 2026
- Improper Validation of Query Parameters in Auth0 Next.js SDK CVE-2025-67716 - Dec 10, 2025
- Improper Request Caching Lookup in the Auth0 Next.js SDK CVE-2025-67490 - Dec 10, 2025
- Improper Memory Cleanup in the Okta Java SDK CVE-2025-66033 - Dec 10, 2025
- Race condition in the Okta Java SDK CVE-2025-67505 - Dec 10, 2025
- Improper HMAC Signature Verification in auth0/node-jws CVE-2025-65945 - Dec 4, 2025
- Improper File Type Handling in Bulk User Import in Auth0 Wordpress plugin CVE-2025-58769 - Oct 1, 2025
- Improper File Type Handling in Bulk User Import in Auth0 Symfony SDK CVE-2025-58769 - Oct 1, 2025
- Improper File Type Handling in Bulk User Import in laravel-auth0 SDK CVE-2025-58769 - Oct 1, 2025
- Improper File Type Handling in Bulk User Import in auth0-PHP SDK CVE-2025-58769 - Oct 1, 2025
- Okta On-Premises Provisioning (OPP) Password Reset Information Disclosure CVE-2025-7371 - Jul 22, 2025
- CDN Caching of Session Cookies in NextJS-Auth0 SDK CVE-2025-48947 - Jun 3, 2025
- Deserialization of Untrusted Data in Auth0-PHP SDK CVE-2025-48951 - Jun 3, 2025
- Deserialization of Untrusted Data in Auth0 Symfony SDK CVE-2025-48951 - Jun 3, 2025
- Deserialization of Untrusted Data in laravel-auth0 SDK CVE-2025-48951 - Jun 3, 2025
- Deserialization of Untrusted Data in Auth0 Wordpress Plugin CVE-2025-48951 - Jun 3, 2025
- Brute Force Authentication Tags of CookieStore Sessions in Auth0-PHP SDK CVE-2025-47275 - May 15, 2025
- Brute Force Authentication Tags of CookieStore Sessions in Auth0 Symfony SDK CVE-2025-47275 - May 15, 2025
- Brute Force Authentication Tags of CookieStore Sessions in Auth0 Wordpress plugin CVE-2025-47275 - May 15, 2025
- Brute Force Authentication Tags of CookieStore Sessions in laravel-auth0 SDK CVE-2025-47275 - May 15, 2025
- SAML Attribute Smuggling Vulnerability Allowing User Impersonation in Passport-WS-Fed CVE-2025-46573 - May 6, 2025
- SAML Signature Wrapping Vulnerability Leading to User Impersonation in Passport-WS-Fed CVE-2025-46572 - May 6, 2025
- JWT Invalid Signature Validation in Auth0 Account Linking Extensions CVE-2025-46345 - Apr 30, 2025
- Okta Verify Desktop MFA for Windows Passwordless Login CVE-2024-9191 - Nov 1, 2024
- Okta AD/LDAP Delegated Authentication - Username Above 52 Characters Security Advisory - Nov 1, 2024
- Okta Verify for iOS ContextExtension CVE-2024-10327 - Oct 24, 2024
- Okta Classic Application Sign-On Policy Bypass - Oct 4, 2024
- Okta Verify for Windows Privilege Escalation CVE-2024-7061 - Aug 7, 2024
- Okta Browser Plugin Reflected Cross-Site Scripting CVE-2024-0981 - Jul 22, 2024
- Okta Verify for Windows Auto-update Arbitrary Code Execution CVE-2024-0980 - Mar 26, 2024
- Okta LDAP Agent CVE-2023-0392 - Sep 19, 2023
- Okta Advanced Server Access Client CVE-2023-0093 - Feb 22, 2023
- Okta Access Gateway Advisory for CVE-2022-3602 and CVE-2022-3786 - Nov 1, 2022
- Okta Active Directory Agent CVE-2022-1697 - Sep 1, 2022
- Okta Advanced Server Access Client CVE-2022-1030 - Mar 21, 2022
- Okta Advanced Server Access Client CVE-2022-24295 - Feb 17, 2022
- Okta RADIUS Server Agent CVE-2021-45105 - Jan 26, 2022
- Okta On-Prem MFA Agent CVE-2021-45046 - Jan 26, 2022
- Okta RADIUS Server Agent CVE-2021-45046 - Jan 26, 2022
- Okta On-Prem MFA Agent CVE-2021-44228 - Jan 26, 2022
- Okta RADIUS Server Agent CVE-2021-44228 - Jan 26, 2022
- Okta On-Prem MFA Agent CVE-2021-45105 - Jan 26, 2022
- Okta Access Gateway CVE-2021-28113 - Apr 2, 2021