---
id: CVE-2026-78579
title: >-
  The Okta Access Gateway does not sanitize SAML assertion attribute values
  before interpolating them into LDAP search filters in the LDAP datastore
  configuration
summary: >-
  The Okta Access Gateway does not sanitize SAML assertion attribute values
  before interpolating them into LDAP search filters in the LDAP datastore
  configuration. The raw values are substituted directly into the filter string
  and passed t…
severity: medium
cvss: 6.8
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N'
cwe:
  - CWE-90
vendor: okta
product: access_gateway
affected:
  - access_gateway < 2026.9.1
patched:
  - access_gateway 2026.9.1
published: '2026-09-08'
updated: '2026-09-23'
sourceUpdated: '2026-09-23T18:17:08.527'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-78579'
references:
  - url: >-
      https://trust.okta.com/security-advisories/improper-input-sanitization-in-okta-access-gateway-ldap-datastore-filter-interpolation-cve-2026-78579
    label: psirt@okta.com
tags:
  - nvd
  - cve.org
epss: 0.00235
epssPercentile: 0.12915
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-10T14:37:45.517123Z'
ingestedAt: '2026-09-08T21:11:12.319Z'
---

## Overview

The Okta Access Gateway does not sanitize SAML assertion attribute values before interpolating them into LDAP search filters in the LDAP datastore configuration. The raw values are substituted directly into the filter string and passed to the LDAP search operation, resulting in modification of the intended query logic.

## Affected

- `access_gateway < 2026.9.1`

## Remediation

Upgrade past the affected range:

- `access_gateway 2026.9.1`
