CVE-2026-78626: Improper Input Sanitization in Okta Access Gateway Protected Rules
The Okta Access Gateway improperly handles input sanitization and regular expression evaluation within its Protected Rule authorization check, resulting in an authorization bypass when an administrator has explicitly configured a Protected Rule policy on one or more application resources.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Okta Access Gatewayto a version that resolves this vulnerability.Fixed in 2026.9.1
Event History
Frequently Asked Questions
Which deployments are exposed to this authorization bypass?
Exposure requires an Okta Access Gateway deployment where an administrator has explicitly configured a Protected Rule policy for one or more application resources. The provided information does not indicate that deployments without Protected Rules are affected.
What level of access does an attacker need?
The vector indicates network-based exploitation with low attack complexity and no user interaction. It also indicates that the attacker needs low privileges.
What is the potential impact if exploitation succeeds?
Successful exploitation can bypass authorization checks protecting affected application resources. The supplied severity vector indicates high confidentiality and integrity impact, with no availability impact indicated.