Improper Input Sanitization in Okta Access Gateway Protected Rules CVE-2026-78626 - Sep 8, 2026
Description
The Okta Access Gateway improperly handles input sanitization and regular expression evaluation within its Protected Rule authorization check, resulting in an authorization bypass when an administrator has explicitly configured a Protected Rule policy on one or more application resources.
Affected product and versions
Customers using the Okta Access Gateway versions prior to 2026.9.1 are affected.
Preconditions
This applies if the following preconditions are present:
A Protected Rule policy is actively configured on one or more application resources.
An authenticated user holds a valid account assigned to the application at any privilege level.
Customer Recommendations
To remediate this vulnerability, upgrade Okta Access Gateway to version 2026.9.1 or greater.
Resolution
The vulnerability is present in Okta Access Gateway versions prior to 2026.9.1 and is resolved in version 2026.9.1.
CVE details
CVE ID | |
Published Date | 2026-09-08 |
Vulnerability Type | Authorization Bypass |
CWE | CWE-863 – Incorrect Authorization |
CVSS v3 | Score: 8.1 Vector string: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N |