Okta Access Gateway 的 Kerberos 配置处理器在将事件负载(event payloads)中指定的文件路径直接作为写入目标,而未对这些路径进行校验,从而导致文件被写入到设备文件系统中非预期的位置。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Okta | Okta Access Gateway | 0 ~ 2026.9.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-78626 | 8.1 HIGH | Improper Input Sanitization in Okta Access Gateway Protected Rules |
| CVE-2026-78623 | 7.7 HIGH | Improper Handling of SAML Assertion Attributes in Okta Access Gateway Advanced Mode Datast |
| CVE-2026-78574 | 7.5 HIGH | Improper Assembly Resolution in Okta Hyperdrive Integration Plugin Registry Handling |
| CVE-2026-78627 | 7.3 HIGH | Improper Credential Protection in Okta Hyperdrive Integration Installer Logging |
| CVE-2026-78579 | 6.8 MEDIUM | Improper Input Sanitization in Okta Access Gateway LDAP Datastore Filter Interpolation |
| CVE-2026-78625 | 6.7 MEDIUM | Insufficient Validation of Dashboard Application Labels in Okta Access Gateway Dashboard S |
| CVE-2026-78630 | 6.7 MEDIUM | Improper Input Neutralization in Okta Access Gateway SNMP Configuration Processing |
| CVE-2026-78550 | 6.6 MEDIUM | Improper Input Handling in Okta Access Gateway Management Console Exception Handler |
| CVE-2026-78545 | 6.6 MEDIUM | Improper Input Sanitization in Okta Access Gateway Application Label Configuration |
| CVE-2026-78552 | 6.0 MEDIUM | Validation Bypass in Okta Access Gateway Custom Directives |
| CVE-2026-78622 | 6.0 MEDIUM | Improper Link Resolution in Okta Verify for Windows Uninstaller Data Removal |
| CVE-2026-78629 | 5.6 MEDIUM | Improper Authentication Verification in the Okta Hyperdrive Agent MFA Response Handling |
| CVE-2026-78631 | 5.3 MEDIUM | Improper Restriction of Sensitive Information in Okta Hyperdrive Agent Logging |
| CVE-2026-78635 | 5.0 MEDIUM | Improper Input Validation in the Okta Privileged Access SSH Client URL Handler Argument |
| CVE-2026-78624 | 4.9 MEDIUM | Improper Path Validation in Okta Access Gateway Backup and Restore Functionality |
| CVE-2026-78560 | 4.8 MEDIUM | Improper Authentication Validation in Okta Access Gateway Pass-Through Authentication Sour |
No comments yet