SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-78625

MEDIUM · CVSS 6.7 EPSS 0.16%

Source: NVD + CISA KEV + EPSS · Published 2026-09-08 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The vulnerability affects the Okta Access Gateway, where unsanitized dashboard label values can be written into PHP configuration files. This flaw allows for potential code execution with the privileges of the web server process, posing a risk of unauthorized access or manipulation during authentication requests. Organizations utilizing Okta Access Gateway should prioritize addressing this issue to mitigate potential security breaches.

CVE
CVE-2026-78625
Severity
MEDIUM
CVSS
6.7
EPSS
0.16%

Original NVD Description

The Okta Access Gateway does not sanitize dashboard label values before writing them into generated PHP configuration files. The generated file is automatically included during authentication requests, resulting in execution with the privileges of the web server process.