HomepageOkta logo

Improper Input Sanitization in Okta Access Gateway Protected Rules CVE-2026-78626 - Sep 8, 2026

View all security advisories

Description

The Okta Access Gateway improperly handles input sanitization and regular expression evaluation within its Protected Rule authorization check, resulting in an authorization bypass when an administrator has explicitly configured a Protected Rule policy on one or more application resources. 

Affected product and versions

Customers using the Okta Access Gateway versions prior to 2026.9.1 are affected.

Preconditions

This applies if the following preconditions are present:

  1. A Protected Rule policy is actively configured on one or more application resources.

  2. An authenticated user holds a valid account assigned to the application at any privilege level.

Customer Recommendations

To remediate this vulnerability, upgrade Okta Access Gateway to version 2026.9.1 or greater.

Resolution

The vulnerability is present in Okta Access Gateway versions prior to 2026.9.1 and is resolved in version 2026.9.1.

CVE details

CVE ID

CVE-2026-78626

Published Date

2026-09-08

Vulnerability Type

Authorization Bypass

CWE

CWE-863 – Incorrect Authorization

CVSS v3

Score: 8.1

Vector string: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

References

Download the Okta Access Gateway image