CVE-2026-78550 MEDIUM

CVE-2026-78550: Improper Input Handling in Okta Access Gateway Management Console Exception Handler

Vendor Okta
Product Okta Access Gateway
Weakness CWE-95 · Eval injection
Published September 8, 2026
Last update September 10, 2026

CVSS base score

6.6/10
Attack vector Network
Attack complexity High
Privileges required High
User interaction None
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H

What the vulnerability does

01Description

The Okta Access Gateway management console passes user-supplied input to eval() without sanitization during an authenticated administrator SSH session. As a result, the unsanitized input is executed directly, leading to code execution with the privileges of the management console.

Key dates

02Disclosure timeline

September 8, 2026 CVE published
September 10, 2026 Record updated

Related vulnerabilities

04Related CVE