CVE-2026-78579
Analyzed Analyzed - Analysis Complete

Okta Access Gateway SAML Attribute Injection in LDAP Search

Vulnerability report for CVE-2026-78579, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-08

Last updated on: 2026-09-23

Assigner: Okta

Description

The Okta Access Gateway does not sanitize SAML assertion attribute values before interpolating them into LDAP search filters in the LDAP datastore configuration. The raw values are substituted directly into the filter string and passed to the LDAP search operation, resulting in modification of the intended query logic.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-08
Last Modified
2026-09-23
Generated
2026-09-30
AI Q&A
2026-09-09
EPSS Evaluated
2026-09-27
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
okta access_gateway to 2026.9.1 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-90 The product constructs all or part of an LDAP query using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended LDAP query when it is sent to a downstream component.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The Okta Access Gateway vulnerability involves improper handling of SAML assertion attribute values. These values are directly inserted into LDAP search filters without sanitization, altering the intended query logic. This could allow attackers to manipulate LDAP queries, potentially accessing unauthorized data or modifying search results.

Impact Analysis

This vulnerability may allow unauthorized access to sensitive data stored in LDAP directories. Attackers could exploit it to retrieve or alter information by crafting malicious SAML assertions. Systems relying on Okta Access Gateway for authentication and LDAP for data storage are at risk.

Compliance Impact

This vulnerability could lead to unauthorized data exposure, violating GDPR's data protection principles or HIPAA's security requirements for protected health information. Non-compliance may result in legal penalties, reputational damage, and loss of trust in data handling practices.

Mitigation Strategies

Apply the latest Okta Access Gateway patch or update to address the SAML assertion sanitization issue in LDAP search filters. Review and restrict LDAP datastore configurations to ensure proper input validation for SAML attributes.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-78579. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart