CVE-2026-78626: Okta Access Gateway
Medium severity, CVSS 6.5. EPSS: 0.4% chance of exploitation in the next 30 days.
The Okta Access Gateway improperly handles input sanitization and regular expression evaluation within its Protected Rule authorization check, resulting in an authorization bypass when an administrator has explicitly configured a Protected Rule policy on one or more application resources.
Affected products
- Okta Access Gateway: before 2026.9.1 (fixed in 2026.9.1)
Published 2026-09-08. Last modified 2026-09-22.