CVE-2026-78550Medium· 6.6▾ SunlitThe Okta Access Gateway management console passes user-supplied input to eval() without sanitization during an authenticated administrator SSH session. As a result, the unsanitized input is executed directly, leading to code execution wi…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 36.3 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Exploit-prediction probability, daily snapshots since Sep 10.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.4%
The Okta Access Gateway management console passes user-supplied input to eval() without sanitization during an authenticated administrator SSH session. As a result, the unsanitized input is executed directly, leading to code execution with the privileges of the management console.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-78545Medium· 6.6The Okta Access Gateway does not sanitize the application label field before including it in the generated nginx configuration file
CVE-2026-78552Medium· 6.0The Okta Access Gateway does not apply its Lua directive restriction to the application-level custom configuration field
CVE-2026-78560Medium· 4.8The Okta Access Gateway includes an optional pass-through authentication source that accepts user identity from a client-supplied HTTP header without cryptographic validation
CVE-2026-78579Medium· 6.8The Okta Access Gateway does not sanitize SAML assertion attribute values before interpolating them into LDAP search filters in the LDAP datastore configuration
CVE-2026-78635Medium· 5.0The Okta Privileged Access client URL handler does not insert an option terminator before appending the target value to the command-line arguments
CVE-2026-78631Medium· 5.3The Okta Hyperdrive Agent writes the decoded SAML bearer assertion to a local application log file at the default log level on every successful MFA completion