Okta 访问网关在将应用程序标签(application label)字段包含到生成的 nginx 配置文件中时,未对其进行转义或清洗处理。未清洗的标签值会被直接插值到 nginx server 块指令中,从而导致注入的指令被执行。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Okta | Okta Access Gateway | 0 ~ 2026.9.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-78626 | 8.1 HIGH | Improper Input Sanitization in Okta Access Gateway Protected Rules |
| CVE-2026-78623 | 7.7 HIGH | Improper Handling of SAML Assertion Attributes in Okta Access Gateway Advanced Mode Datast |
| CVE-2026-78574 | 7.5 HIGH | Improper Assembly Resolution in Okta Hyperdrive Integration Plugin Registry Handling |
| CVE-2026-78627 | 7.3 HIGH | Improper Credential Protection in Okta Hyperdrive Integration Installer Logging |
| CVE-2026-78579 | 6.8 MEDIUM | Improper Input Sanitization in Okta Access Gateway LDAP Datastore Filter Interpolation |
| CVE-2026-78625 | 6.7 MEDIUM | Insufficient Validation of Dashboard Application Labels in Okta Access Gateway Dashboard S |
| CVE-2026-78630 | 6.7 MEDIUM | Improper Input Neutralization in Okta Access Gateway SNMP Configuration Processing |
| CVE-2026-78550 | 6.6 MEDIUM | Improper Input Handling in Okta Access Gateway Management Console Exception Handler |
| CVE-2026-78552 | 6.0 MEDIUM | Validation Bypass in Okta Access Gateway Custom Directives |
| CVE-2026-78622 | 6.0 MEDIUM | Improper Link Resolution in Okta Verify for Windows Uninstaller Data Removal |
| CVE-2026-78620 | 5.9 MEDIUM | Improper Path Validation in Okta Access Gateway Kerberos Configuration Handling |
| CVE-2026-78629 | 5.6 MEDIUM | Improper Authentication Verification in the Okta Hyperdrive Agent MFA Response Handling |
| CVE-2026-78631 | 5.3 MEDIUM | Improper Restriction of Sensitive Information in Okta Hyperdrive Agent Logging |
| CVE-2026-78635 | 5.0 MEDIUM | Improper Input Validation in the Okta Privileged Access SSH Client URL Handler Argument |
| CVE-2026-78624 | 4.9 MEDIUM | Improper Path Validation in Okta Access Gateway Backup and Restore Functionality |
| CVE-2026-78560 | 4.8 MEDIUM | Improper Authentication Validation in Okta Access Gateway Pass-Through Authentication Sour |
No comments yet