← Vulnerability feed

Vulnerability record · CVE-2026-78623 · published 8 September 2026

CVE-2026-78623: Okta access gateway sql injection vulnerability

Okta · Access Gateway

The Okta Access Gateway does not sanitize SAML assertion values before interpolating them into database queries in the advanced mode datastore configuration. The unsanitized values are substituted directly into the query string prior to preparation, resulting in unintended SQL execution against the configured backend database.

9.9 CVSS 3.1 Critical EPSS 0.45% · top 63.4% CWE-89 · SQL injection
9.9CVSS 3.1 base score
0.45%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
22 Sep 2026Last modified by NVD

Description

The Okta Access Gateway does not sanitize SAML assertion values before interpolating them into database queries in the advanced mode datastore configuration. The unsanitized values are substituted directly into the query string prior to preparation, resulting in unintended SQL execution against the configured backend database.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-78623 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

6.7CVE-2026-78630Okta access gateway os command injection vulnerabilityThe Okta Access Gateway does not neutralize shell metacharacters in SNMP configuration values before a privileged script uses them to construct OS co…EPSS 0.22%6.7CVE-2026-78625Okta access gateway code injection vulnerabilityThe Okta Access Gateway does not sanitize dashboard label values before writing them into generated PHP configuration files. The generated file is au…EPSS 0.23%6.7CVE-2021-28113Okta access gateway os command injection vulnerabilityA command injection vulnerability in the cookieDomain and relayDomain parameters of Okta Access Gateway before 2020.9.3 allows attackers (with admin …EPSS 22%6.5CVE-2026-78626Okta access gateway incorrect authorization vulnerabilityThe Okta Access Gateway improperly handles input sanitization and regular expression evaluation within its Protected Rule authorization check, result…EPSS 0.36%6.5CVE-2026-78560Okta access gateway improper authentication vulnerabilityThe Okta Access Gateway includes an optional pass-through authentication source that accepts user identity from a client-supplied HTTP header without…EPSS 0.20%6.5CVE-2026-78579Okta access gateway ldap injection vulnerabilityThe Okta Access Gateway does not sanitize SAML assertion attribute values before interpolating them into LDAP search filters in the LDAP datastore co…EPSS 0.24%4.9CVE-2026-78624Okta access gateway path traversal vulnerabilityThe Okta Access Gateway backup restore function does not validate the filename embedded in an encrypted backup payload. This results in writing file …EPSS 0.46%4.9CVE-2026-78552Okta access gateway vulnerabilityThe Okta Access Gateway does not apply its Lua directive restriction to the application-level custom configuration field. The field is interpolated d…EPSS 0.27%

Source: NIST National Vulnerability Database (record CVE-2026-78623), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.