{"id":"CVE-2026-78624","title":"The Okta Access Gateway backup restore function does not validate the filename embedded in an encrypted backup payload","summary":"The Okta Access Gateway backup restore function does not validate the filename embedded in an encrypted backup payload. This results in writing file contents to unintended locations on the appliance filesystem.","severity":"medium","cvss":4.9,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N","cwe":["CWE-22"],"vendor":"Okta","product":"Okta Access Gateway","affected":["access_gateway < 2026.9.1"],"published":"2026-09-08","updated":"2026-09-10","sourceUpdated":"2026-09-10T15:17:41.867","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-78624","references":[{"url":"https://trust.okta.com/security-advisories/improper-path-validation-in-okta-access-gateway-backup-and-restore-functionality-cve-2026-78624","label":"psirt@okta.com"}],"tags":["nvd","cve.org"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-09-10T14:31:34.907896Z"},"epss":0.00352,"epssPercentile":0.28794,"ingestedAt":"2026-09-08T21:11:12.319Z","slug":"CVE-2026-78624","body":"## Overview\n\nThe Okta Access Gateway backup restore function does not validate the filename embedded in an encrypted backup payload. This results in writing file contents to unintended locations on the appliance filesystem.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":27,"depthScoreParts":{"impact":27,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}