CVE-2026-78560 PUBLISHED

Improper Authentication Validation in Okta Access Gateway Pass-Through Authentication Source

Assigner: Okta
Reserved: 24.08.2026 Published: 08.09.2026 Updated: 08.09.2026

The Okta Access Gateway includes an optional pass-through authentication source that accepts user identity from a client-supplied HTTP header without cryptographic validation. In architectures where this optional source is enabled without an upstream reverse proxy or firewall configured to sanitize and enforce client headers, an unauthenticated user can supply an arbitrary identity value to initiate a session.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
CVSS Score: 4.8

Product Status

Vendor Okta
Product Okta Access Gateway
Versions Default: unaffected
  • affected from 0 to 2026.9.1 (excl.)

Solutions

Upgrade the Okta Access Gateway appliance to version 2026.9.1 or greater.

References

Problem Types

  • Improper Authentication