CVE-2026-78560
Analyzed Analyzed - Analysis Complete

Okta Access Gateway Authentication Bypass via HTTP Header

Vulnerability report for CVE-2026-78560, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-08

Last updated on: 2026-09-23

Assigner: Okta

Description

The Okta Access Gateway includes an optional pass-through authentication source that accepts user identity from a client-supplied HTTP header without cryptographic validation. In architectures where this optional source is enabled without an upstream reverse proxy or firewall configured to sanitize and enforce client headers, an unauthenticated user can supply an arbitrary identity value to initiate a session.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-08
Last Modified
2026-09-23
Generated
2026-09-30
AI Q&A
2026-09-09
EPSS Evaluated
2026-09-27
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
okta access_gateway to 2026.9.1 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-287 When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The Okta Access Gateway has an optional feature that allows authentication via a client-supplied HTTP header without proper cryptographic validation. If this feature is enabled and no upstream proxy or firewall is configured to sanitize headers, an attacker can set any identity value to create a session without authentication.

Detection Guidance

Check Okta Access Gateway configurations for enabled pass-through authentication sources without upstream reverse proxy or firewall header sanitization. Inspect HTTP headers for client-supplied identity values in logs or traffic. Look for sessions initiated without proper authentication steps.

Impact Analysis

An attacker could impersonate any user, gaining unauthorized access to systems or data protected by Okta Access Gateway. This could lead to data breaches, unauthorized actions, or further network compromise depending on the user's privileges.

Compliance Impact

This vulnerability could violate compliance requirements for data protection and access control, such as GDPR's integrity and confidentiality principles or HIPAA's access controls. Unauthorized access risks data exposure, potentially leading to regulatory penalties.

Mitigation Strategies

Disable the pass-through authentication source if not required. Configure upstream reverse proxy or firewall to sanitize and enforce client headers. Validate all identity headers cryptographically before session initiation. Review and update access policies to ensure proper authentication.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-78560. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart