SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-78624

MEDIUM · CVSS 4.9 EPSS 0.35%

Source: NVD + CISA KEV + EPSS · Published 2026-09-08 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The vulnerability in the Okta Access Gateway's backup restore function allows an attacker to manipulate the filename in an encrypted backup payload, leading to potential unauthorized file writes to unintended locations on the appliance filesystem. This could compromise the integrity of the system and expose sensitive data. Organizations using Okta Access Gateway should prioritize addressing this issue to mitigate risks associated with unauthorized file access and system integrity breaches.

CVE
CVE-2026-78624
Severity
MEDIUM
CVSS
4.9
EPSS
0.35%

Original NVD Description

The Okta Access Gateway backup restore function does not validate the filename embedded in an encrypted backup payload. This results in writing file contents to unintended locations on the appliance filesystem.