---
id: CVE-2026-78625
title: >-
  The Okta Access Gateway does not sanitize dashboard label values before
  writing them into generated PHP configuration files
summary: >-
  The Okta Access Gateway does not sanitize dashboard label values before
  writing them into generated PHP configuration files. The generated file is
  automatically included during authentication requests, resulting in execution
  with the pri…
severity: medium
cvss: 6.7
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-94
vendor: okta
product: access_gateway
affected:
  - access_gateway < 2026.9.1
patched:
  - access_gateway 2026.9.1
published: '2026-09-08'
updated: '2026-09-22'
sourceUpdated: '2026-09-22T20:16:41.267'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-78625'
references:
  - url: >-
      https://trust.okta.com/security-advisories/insufficient-validation-of-dashboard-application-labels-in-okta-access-gateway-dashboard-site-configuration-cve-2026-78625
    label: psirt@okta.com
tags:
  - nvd
  - cve.org
epss: 0.00229
epssPercentile: 0.12244
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-10T14:34:46.618350Z'
ingestedAt: '2026-09-08T21:11:12.319Z'
---

## Overview

The Okta Access Gateway does not sanitize dashboard label values before writing them into generated PHP configuration files. The generated file is automatically included during authentication requests, resulting in execution with the privileges of the web server process.

## Affected

- `access_gateway < 2026.9.1`

## Remediation

Upgrade past the affected range:

- `access_gateway 2026.9.1`
