CVE-2026-78624 PUBLISHED

Improper Path Validation in Okta Access Gateway Backup and Restore Functionality

Assigner: Okta
Reserved: 24.08.2026 Published: 08.09.2026 Updated: 08.09.2026

The Okta Access Gateway backup restore function does not validate the filename embedded in an encrypted backup payload. This results in writing file contents to unintended locations on the appliance filesystem.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
CVSS Score: 4.9

Product Status

Vendor Okta
Product Okta Access Gateway
Versions Default: unaffected
  • affected from 0 to 2026.9.1 (excl.)

Solutions

Upgrade the Okta Access Gateway appliance to version 2026.9.1 or greater.

References

Problem Types

  • Improper Limitation of a Pathname to a Restricted Directory