CVE-2026-78552: Okta Access Gateway

Medium severity, CVSS 4.9. EPSS: 0.3% chance of exploitation in the next 30 days.

The Okta Access Gateway does not apply its Lua directive restriction to the application-level custom configuration field. The field is interpolated directly into the nginx server block without inspection, resulting in execution of injected directives.

Affected products

  • Okta Access Gateway: before 2026.9.1 (fixed in 2026.9.1)

Published 2026-09-08. Last modified 2026-09-23.