SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-78626

HIGH · CVSS 8.1 EPSS 0.21%

Source: NVD + CISA KEV + EPSS · Published 2026-09-08 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The vulnerability in Okta Access Gateway arises from improper input sanitization and regular expression evaluation during the Protected Rule authorization check, allowing unauthorized access to application resources when a Protected Rule policy is configured. This can lead to significant security risks, as attackers may bypass authorization controls, potentially exposing sensitive data or functionalities. Organizations utilizing Okta Access Gateway should prioritize remediation efforts to mitigate the risk of exploitation.

CVE
CVE-2026-78626
Severity
HIGH
CVSS
8.1
EPSS
0.21%

Original NVD Description

The Okta Access Gateway improperly handles input sanitization and regular expression evaluation within its Protected Rule authorization check, resulting in an authorization bypass when an administrator has explicitly configured a Protected Rule policy on one or more application resources.