---
id: CVE-2026-78620
title: >-
  The Okta Access Gateway Kerberos configuration handler does not validate file
  paths specified in event payloads before writing file contents
summary: >-
  The Okta Access Gateway Kerberos configuration handler does not validate file
  paths specified in event payloads before writing file contents. The path from
  the event payload is used directly as the write destination, resulting in
  files b…
severity: medium
cvss: 5.9
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N'
cwe:
  - CWE-73
vendor: okta
product: access_gateway
affected:
  - access_gateway < 2026.9.1
patched:
  - access_gateway 2026.9.1
published: '2026-09-08'
updated: '2026-09-22'
sourceUpdated: '2026-09-22T20:39:20.293'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-78620'
references:
  - url: >-
      https://trust.okta.com/security-advisories/improper-path-validation-in-okta-access-gateway-kerberos-configuration-handling-cve-2026-78620
    label: psirt@okta.com
tags:
  - nvd
  - cve.org
epss: 0.00338
epssPercentile: 0.24418
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-10T14:47:51.803109Z'
ingestedAt: '2026-09-08T21:11:12.319Z'
---

## Overview

The Okta Access Gateway Kerberos configuration handler does not validate file paths specified in event payloads before writing file contents. The path from the event payload is used directly as the write destination, resulting in files being written to unintended locations on the appliance filesystem.

## Affected

- `access_gateway < 2026.9.1`

## Remediation

Upgrade past the affected range:

- `access_gateway 2026.9.1`
