Okta Access Gateway 包含一个可选的直通认证源,该源接受客户端通过 HTTP 请求头提供的用户身份,且未进行加密验证。在启用此可选源但未配置上游反向代理或防火墙来清洗并强制处理客户端请求头的环境中,未认证的用户可以提供任意的身份值以发起会话。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Okta | Okta Access Gateway | 0 ~ 2026.9.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-78626 | 8.1 HIGH | Improper Input Sanitization in Okta Access Gateway Protected Rules |
| CVE-2026-78623 | 7.7 HIGH | Improper Handling of SAML Assertion Attributes in Okta Access Gateway Advanced Mode Datast |
| CVE-2026-78574 | 7.5 HIGH | Improper Assembly Resolution in Okta Hyperdrive Integration Plugin Registry Handling |
| CVE-2026-78627 | 7.3 HIGH | Improper Credential Protection in Okta Hyperdrive Integration Installer Logging |
| CVE-2026-78579 | 6.8 MEDIUM | Improper Input Sanitization in Okta Access Gateway LDAP Datastore Filter Interpolation |
| CVE-2026-78625 | 6.7 MEDIUM | Insufficient Validation of Dashboard Application Labels in Okta Access Gateway Dashboard S |
| CVE-2026-78630 | 6.7 MEDIUM | Improper Input Neutralization in Okta Access Gateway SNMP Configuration Processing |
| CVE-2026-78550 | 6.6 MEDIUM | Improper Input Handling in Okta Access Gateway Management Console Exception Handler |
| CVE-2026-78545 | 6.6 MEDIUM | Improper Input Sanitization in Okta Access Gateway Application Label Configuration |
| CVE-2026-78552 | 6.0 MEDIUM | Validation Bypass in Okta Access Gateway Custom Directives |
| CVE-2026-78622 | 6.0 MEDIUM | Improper Link Resolution in Okta Verify for Windows Uninstaller Data Removal |
| CVE-2026-78620 | 5.9 MEDIUM | Improper Path Validation in Okta Access Gateway Kerberos Configuration Handling |
| CVE-2026-78629 | 5.6 MEDIUM | Improper Authentication Verification in the Okta Hyperdrive Agent MFA Response Handling |
| CVE-2026-78631 | 5.3 MEDIUM | Improper Restriction of Sensitive Information in Okta Hyperdrive Agent Logging |
| CVE-2026-78635 | 5.0 MEDIUM | Improper Input Validation in the Okta Privileged Access SSH Client URL Handler Argument |
| CVE-2026-78624 | 4.9 MEDIUM | Improper Path Validation in Okta Access Gateway Backup and Restore Functionality |
No comments yet