Improper Path Validation in Okta Access Gateway Backup and Restore Functionality CVE-2026-78624 - Sep 8, 2026
Description
The Okta Access Gateway backup restore function does not validate the filename embedded in an encrypted backup payload. This results in writing file contents to unintended locations on the appliance filesystem.
Affected product and versions
Customers using the Okta Access Gateway appliance versions prior to 2026.9.1 are affected.
Preconditions
This applies if the following preconditions are present:
The Okta Access Gateway administrative management interface is network-reachable,
An authenticated user holds administrator privileges with authorization to upload and restore appliance backup files.
Customer Recommendations
To remediate this vulnerability, upgrade the Okta Access Gateway appliance to version 2026.9.1 or greater.
Resolution
The vulnerability is present in the Okta Access Gateway appliance versions prior to 2026.9.1 and is resolved in version 2026.9.1.
CVE details
CVE ID | |
Published Date | 2026-09-08 |
Vulnerability Type | Path Traversal |
CWE | CWE-22 – Improper Limitation of a Pathname to a Restricted Directory |
CVSS v3 | Score: 4.9 Vector string: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N |