CVE-2026-33376: Auth Proxy IPv6 whitelist bypass
When using an IPv6 allow-list for the Auth Proxy feature, it defaults to /32 addresses. Addresses specifying a mask explicitly are not affected; to mitigate easily, add the desired mask (usually /128) to the addresses. Only auth proxy is affected; Okta, SAML, LDAP, etc are unaffected here.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
When using an IPv6 allow-list for the Auth Proxy feature, add the desired mask (usually /128) to the allowed addresses so they are not implicitly treated as default /32 prefixes, which enables whitelist bypass.
Auth Proxy IPv6 allow-list IPv6 address mask (prefix length) = /128
Event History
Frequently Asked Questions
What is the severity of CVE-2026-33376?
CVE-2026-33376 has a severity rating of high at 7.4.
How do I fix CVE-2026-33376?
To fix CVE-2026-33376, add /128 masks to the IPv6 addresses on the Auth Proxy allow-list.
What type of vulnerability is CVE-2026-33376?
CVE-2026-33376 is a vulnerability related to an IPv6 whitelist bypass in the Auth Proxy feature.
Which features are affected by CVE-2026-33376?
Only the Auth Proxy feature is affected by CVE-2026-33376; other features like Okta, SAML, and LDAP are unaffected.
When was CVE-2026-33376 published?
CVE-2026-33376 was published on May 13, 2026.