CVE-2026-78552 MEDIUM

CVE-2026-78552: Validation Bypass in Okta Access Gateway Custom Directives

Vendor Okta
Product Okta Access Gateway
Weakness CWE-693
Published September 8, 2026
Last update September 10, 2026

CVSS base score

6.0/10
Attack vector Network
Attack complexity Low
Privileges required High
User interaction None
Confidentiality Low
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:L

What the vulnerability does

01Description

The Okta Access Gateway does not apply its Lua directive restriction to the application-level custom configuration field. The field is interpolated directly into the nginx server block without inspection, resulting in execution of injected directives.

Key dates

02Disclosure timeline

September 8, 2026 CVE published
September 10, 2026 Record updated