CVE-2026-78623
Analyzed Analyzed - Analysis Complete

SQL Injection in Okta Access Gateway via SAML Assertions

Vulnerability report for CVE-2026-78623, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-08

Last updated on: 2026-09-22

Assigner: Okta

Description

The Okta Access Gateway does not sanitize SAML assertion values before interpolating them into database queries in the advanced mode datastore configuration. The unsanitized values are substituted directly into the query string prior to preparation, resulting in unintended SQL execution against the configured backend database.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-08
Last Modified
2026-09-22
Generated
2026-09-29
AI Q&A
2026-09-10
EPSS Evaluated
2026-09-27
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
okta access_gateway to 2026.9.1 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-89 The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The Okta Access Gateway has a flaw where SAML assertion values are not properly sanitized before being used in database queries when advanced mode datastore configuration is enabled. This allows unsanitized input to be directly inserted into query strings, which can lead to unintended SQL commands being executed against the backend database.

Impact Analysis

This vulnerability could allow an attacker with access to craft malicious SAML assertions to execute unauthorized SQL commands. This may result in data breaches, unauthorized data access, or manipulation of database contents, potentially leading to further compromise of the system or sensitive information.

Compliance Impact

This vulnerability could lead to unauthorized access or exposure of sensitive data, violating requirements for data protection and confidentiality under GDPR and HIPAA. Organizations using the affected Okta Access Gateway may face compliance violations, legal penalties, and reputational damage due to potential data breaches.

Mitigation Strategies

Disable advanced mode datastore configuration in Okta Access Gateway to prevent unsanitized SAML assertion values from being interpolated into database queries.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-78623. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart