CVE-2026-78625

Summary

The Okta Access Gateway does not sanitize dashboard label values before writing them into generated PHP configuration files. The generated file is automatically included during authentication requests, resulting in execution with the privileges of the web server process.

Affected Software

VendorProductVersion RangeStatus
OktaOkta Access Gateway0 < 2026.9.1affected

Weaknesses

  • CWE-94: Improper Control of Generation of Code

References