---
id: CVE-2026-78545
title: >-
  The Okta Access Gateway does not sanitize the application label field before
  including it in the generated nginx configuration file
summary: >-
  The Okta Access Gateway does not sanitize the application label field before
  including it in the generated nginx configuration file. The unsanitized value
  is interpolated into an nginx server block directive, resulting in execution
  of in…
severity: medium
cvss: 6.6
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-94
vendor: Okta
product: Okta Access Gateway
affected:
  - access_gateway < 2026.9.1
published: '2026-09-08'
updated: '2026-09-10'
sourceUpdated: '2026-09-10T19:17:34.710'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-78545'
references:
  - url: >-
      https://trust.okta.com/security-advisories/improper-input-sanitization-in-okta-access-gateway-application-label-configuration-cve-2026-78545/
    label: psirt@okta.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-10T18:00:45.406892Z'
epss: 0.00491
epssPercentile: 0.39513
ingestedAt: '2026-09-08T21:11:12.319Z'
---

## Overview

The Okta Access Gateway does not sanitize the application label field before including it in the generated nginx configuration file. The unsanitized value is interpolated into an nginx server block directive, resulting in execution of injected directives.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
