CVE-2026-78545
Undergoing Analysis Undergoing Analysis - In Progress

Okta Access Gateway Nginx Configuration Injection Vulnerability

Vulnerability report for CVE-2026-78545, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-08

Last updated on: 2026-09-29

Assigner: Okta

Description

The Okta Access Gateway does not sanitize the application label field before including it in the generated nginx configuration file. The unsanitized value is interpolated into an nginx server block directive, resulting in execution of injected directives.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-08
Last Modified
2026-09-29
Generated
2026-09-29
AI Q&A
2026-09-10
EPSS Evaluated
2026-09-27
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
okta access_gateway to 2026.9.1 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-94 The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The Okta Access Gateway has a vulnerability where it fails to properly sanitize the application label field. This unsanitized input is then inserted into an nginx server block configuration, allowing attackers to inject malicious nginx directives that could be executed.

Detection Guidance

Check nginx configuration files for unsanitized application label fields in server block directives. Look for unusual or unexpected directives in the configuration that may indicate injection. Review Okta Access Gateway logs for any suspicious activity related to configuration generation.

Impact Analysis

This vulnerability could allow attackers to execute arbitrary commands or modify server configurations by injecting malicious nginx directives. This may lead to unauthorized access, data breaches, or service disruption depending on the attacker's goals.

Mitigation Strategies

Apply the latest security patch from Okta to address the unsanitized input issue. Review and sanitize all application label fields in the Okta Access Gateway configuration. Monitor nginx configuration files for unauthorized changes and restrict access to configuration generation tools.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-78545. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart