---
id: CVE-2026-78624
title: >-
  The Okta Access Gateway backup restore function does not validate the filename
  embedded in an encrypted backup payload
summary: >-
  The Okta Access Gateway backup restore function does not validate the filename
  embedded in an encrypted backup payload. This results in writing file contents
  to unintended locations on the appliance filesystem.
severity: medium
cvss: 4.9
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-22
vendor: okta
product: access_gateway
affected:
  - access_gateway < 2026.9.1
patched:
  - access_gateway 2026.9.1
published: '2026-09-08'
updated: '2026-09-22'
sourceUpdated: '2026-09-22T20:19:15.390'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-78624'
references:
  - url: >-
      https://trust.okta.com/security-advisories/improper-path-validation-in-okta-access-gateway-backup-and-restore-functionality-cve-2026-78624
    label: psirt@okta.com
tags:
  - nvd
  - cve.org
epss: 0.00331
epssPercentile: 0.26438
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-10T14:31:34.907896Z'
ingestedAt: '2026-09-08T21:11:12.319Z'
---

## Overview

The Okta Access Gateway backup restore function does not validate the filename embedded in an encrypted backup payload. This results in writing file contents to unintended locations on the appliance filesystem.

## Affected

- `access_gateway < 2026.9.1`

## Remediation

Upgrade past the affected range:

- `access_gateway 2026.9.1`
