CVE-2026-78624: Improper Path Validation in Okta Access Gateway Backup and Restore Functionality
The Okta Access Gateway backup restore function does not validate the filename embedded in an encrypted backup payload. This results in writing file contents to unintended locations on the appliance filesystem.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Okta Access Gatewayto a version that resolves this vulnerability.Fixed in 2026.9.1
Event History
Frequently Asked Questions
What level of access does an attacker need to exploit this issue?
The vulnerability requires high privileges. The available data does not identify the specific role or interface needed to perform a backup restore.
Can this be exploited remotely without user interaction?
Yes. The CVSS vector indicates network-based exploitation, low attack complexity, and no user interaction requirement.
What is the likely security impact?
A successful exploit can write file contents to unintended locations on the appliance filesystem, resulting in high confidentiality impact. The provided scoring indicates no integrity or availability impact.