{"id":"CVE-2026-78545","title":"The Okta Access Gateway does not sanitize the application label field before including it in the generated nginx configuration file","summary":"The Okta Access Gateway does not sanitize the application label field before including it in the generated nginx configuration file. The unsanitized value is interpolated into an nginx server block directive, resulting in execution of in…","severity":"medium","cvss":6.6,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-94"],"vendor":"Okta","product":"Okta Access Gateway","affected":["access_gateway < 2026.9.1"],"published":"2026-09-08","updated":"2026-09-10","sourceUpdated":"2026-09-10T19:17:34.710","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-78545","references":[{"url":"https://trust.okta.com/security-advisories/improper-input-sanitization-in-okta-access-gateway-application-label-configuration-cve-2026-78545/","label":"psirt@okta.com"}],"tags":["nvd","cve.org"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"total","timestamp":"2026-09-10T18:00:45.406892Z"},"epss":0.00357,"epssPercentile":0.29495,"ingestedAt":"2026-09-08T21:11:12.319Z","slug":"CVE-2026-78545","body":"## Overview\n\nThe Okta Access Gateway does not sanitize the application label field before including it in the generated nginx configuration file. The unsanitized value is interpolated into an nginx server block directive, resulting in execution of injected directives.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":36,"depthScoreParts":{"impact":36.3,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}