---
id: CVE-2026-78626
title: >-
  The Okta Access Gateway improperly handles input sanitization and regular
  expression evaluation within its Protected Rule authorization check, resulting
  in an authorization bypass when an administrator has explicitly configured a
  Protect…
summary: >-
  The Okta Access Gateway improperly handles input sanitization and regular
  expression evaluation within its Protected Rule authorization check, resulting
  in an authorization bypass when an administrator has explicitly configured a
  Protect…
severity: high
cvss: 8.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'
cwe:
  - CWE-863
vendor: okta
product: access_gateway
affected:
  - access_gateway < 2026.9.1
patched:
  - access_gateway 2026.9.1
published: '2026-09-08'
updated: '2026-09-22'
sourceUpdated: '2026-09-22T20:14:53.140'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-78626'
references:
  - url: >-
      https://trust.okta.com/security-advisories/improper-input-sanitization-in-okta-access-gateway-protected-rules-cve-2026-78626
    label: psirt@okta.com
tags:
  - nvd
  - cve.org
epss: 0.00358
epssPercentile: 0.26867
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-10T14:35:14.242507Z'
ingestedAt: '2026-09-08T21:11:12.320Z'
---

## Overview

The Okta Access Gateway improperly handles input sanitization and regular expression evaluation within its Protected Rule authorization check, resulting in an authorization bypass when an administrator has explicitly configured a Protected Rule policy on one or more application resources.

## Affected

- `access_gateway < 2026.9.1`

## Remediation

Upgrade past the affected range:

- `access_gateway 2026.9.1`
