SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-78620

MEDIUM · CVSS 5.9 EPSS 0.25%

Source: NVD + CISA KEV + EPSS · Published 2026-09-08 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The Okta Access Gateway's Kerberos configuration handler is vulnerable due to improper validation of file paths in event payloads, allowing attackers to manipulate file write destinations on the appliance filesystem. This could lead to unauthorized file creation or overwriting, potentially compromising the integrity of the system. Organizations using Okta Access Gateway should prioritize addressing this vulnerability to mitigate risks associated with file system manipulation.

CVE
CVE-2026-78620
Severity
MEDIUM
CVSS
5.9
EPSS
0.25%

Original NVD Description

The Okta Access Gateway Kerberos configuration handler does not validate file paths specified in event payloads before writing file contents. The path from the event payload is used directly as the write destination, resulting in files being written to unintended locations on the appliance filesystem.