HomepageOkta logo

Improper Path Validation in Okta Access Gateway Backup and Restore Functionality CVE-2026-78624 - Sep 8, 2026

View all security advisories

Description

The Okta Access Gateway backup restore function does not validate the filename embedded in an encrypted backup payload. This results in writing file contents to unintended locations on the appliance filesystem.

Affected product and versions

Customers using the Okta Access Gateway appliance versions prior to 2026.9.1 are affected.

Preconditions

This applies if the following preconditions are present:

  1. The Okta Access Gateway administrative management interface is network-reachable,

  2. An authenticated user holds administrator privileges with authorization to upload and restore appliance backup files.

Customer Recommendations

To remediate this vulnerability, upgrade the Okta Access Gateway appliance to version 2026.9.1 or greater. 

Resolution

The vulnerability is present in the Okta Access Gateway appliance versions prior to 2026.9.1 and is resolved in version 2026.9.1.

CVE details

CVE ID

CVE-2026-78624

Published Date

2026-09-08

Vulnerability Type

Path Traversal

CWE

CWE-22 – Improper Limitation of a Pathname to a Restricted Directory

CVSS v3

Score: 4.9

Vector string: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

References

Download the Okta Access Gateway image