Every CVE whose affected-product data names Okta Access Gateway, ordered by CVSS severity, with EPSS exploit prediction and CISA KEV status.
CVEs (12)
CVE-2026-78626 — CVSS 8.1 (high): The Okta Access Gateway improperly handles input sanitization and regular expression evaluation within its Protected Rule authorization…
CVE-2026-78623 — CVSS 7.7 (high): The Okta Access Gateway does not sanitize SAML assertion values before interpolating them into database queries in the advanced mode…
CVE-2026-78579 — CVSS 6.8 (medium): The Okta Access Gateway does not sanitize SAML assertion attribute values before interpolating them into LDAP search filters in the LDAP…
CVE-2021-28113 — CVSS 6.7 (medium): A command injection vulnerability in the cookieDomain and relayDomain parameters of Okta Access Gateway before 2020.9.3 allows attackers…
CVE-2026-78625 — CVSS 6.7 (medium): The Okta Access Gateway does not sanitize dashboard label values before writing them into generated PHP configuration files. The generated…
CVE-2026-78630 — CVSS 6.7 (medium): The Okta Access Gateway does not neutralize shell metacharacters in SNMP configuration values before a privileged script uses them to…
CVE-2026-78550 — CVSS 6.6 (medium): The Okta Access Gateway management console passes user-supplied input to eval() without sanitization during an authenticated administrator…
CVE-2026-78545 — CVSS 6.6 (medium): The Okta Access Gateway does not sanitize the application label field before including it in the generated nginx configuration file. The…
CVE-2026-78552 — CVSS 6.0 (medium): The Okta Access Gateway does not apply its Lua directive restriction to the application-level custom configuration field. The field is…
CVE-2026-78620 — CVSS 5.9 (medium): The Okta Access Gateway Kerberos configuration handler does not validate file paths specified in event payloads before writing file…
CVE-2026-78624 — CVSS 4.9 (medium): The Okta Access Gateway backup restore function does not validate the filename embedded in an encrypted backup payload. This results in…
CVE-2026-78560 — CVSS 4.8 (medium): The Okta Access Gateway includes an optional pass-through authentication source that accepts user identity from a client-supplied HTTP…