Okta Access Gateway 未在中特化脚本使用 SNMP 配置值构建操作系统命令前,对配置值中的 shell 元字符进行转义或过滤。拥有管理界面访问权限的已认证本地用户可输入特制的配置值,从而以 root 权限执行任意操作系统命令。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Okta | Okta Access Gateway | 0 ~ 2026.9.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-78626 | 8.1 HIGH | Improper Input Sanitization in Okta Access Gateway Protected Rules |
| CVE-2026-78623 | 7.7 HIGH | Improper Handling of SAML Assertion Attributes in Okta Access Gateway Advanced Mode Datast |
| CVE-2026-78574 | 7.5 HIGH | Improper Assembly Resolution in Okta Hyperdrive Integration Plugin Registry Handling |
| CVE-2026-78627 | 7.3 HIGH | Improper Credential Protection in Okta Hyperdrive Integration Installer Logging |
| CVE-2026-78579 | 6.8 MEDIUM | Improper Input Sanitization in Okta Access Gateway LDAP Datastore Filter Interpolation |
| CVE-2026-78625 | 6.7 MEDIUM | Insufficient Validation of Dashboard Application Labels in Okta Access Gateway Dashboard S |
| CVE-2026-78550 | 6.6 MEDIUM | Improper Input Handling in Okta Access Gateway Management Console Exception Handler |
| CVE-2026-78545 | 6.6 MEDIUM | Improper Input Sanitization in Okta Access Gateway Application Label Configuration |
| CVE-2026-78552 | 6.0 MEDIUM | Validation Bypass in Okta Access Gateway Custom Directives |
| CVE-2026-78622 | 6.0 MEDIUM | Improper Link Resolution in Okta Verify for Windows Uninstaller Data Removal |
| CVE-2026-78620 | 5.9 MEDIUM | Improper Path Validation in Okta Access Gateway Kerberos Configuration Handling |
| CVE-2026-78629 | 5.6 MEDIUM | Improper Authentication Verification in the Okta Hyperdrive Agent MFA Response Handling |
| CVE-2026-78631 | 5.3 MEDIUM | Improper Restriction of Sensitive Information in Okta Hyperdrive Agent Logging |
| CVE-2026-78635 | 5.0 MEDIUM | Improper Input Validation in the Okta Privileged Access SSH Client URL Handler Argument |
| CVE-2026-78624 | 4.9 MEDIUM | Improper Path Validation in Okta Access Gateway Backup and Restore Functionality |
| CVE-2026-78560 | 4.8 MEDIUM | Improper Authentication Validation in Okta Access Gateway Pass-Through Authentication Sour |
No comments yet