SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-78552

MEDIUM · CVSS 6 EPSS 0.33%

Source: NVD + CISA KEV + EPSS · Published 2026-09-08 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

Nginx is vulnerable due to a flaw in the Okta Access Gateway, where the Lua directive restriction is not enforced on the application-level custom configuration field, allowing for the execution of injected directives. This could lead to unauthorized command execution, potentially compromising the integrity of the server. Organizations utilizing Okta Access Gateway with Nginx should prioritize this vulnerability to mitigate risks associated with potential exploitation.

CVE
CVE-2026-78552
Severity
MEDIUM
CVSS
6
EPSS
0.33%
Nginx

Original NVD Description

The Okta Access Gateway does not apply its Lua directive restriction to the application-level custom configuration field. The field is interpolated directly into the nginx server block without inspection, resulting in execution of injected directives.