CVE-2026-78626
The Okta Access Gateway improperly handles input sanitization and regular expression evaluation within its Protected Rule authorization check, resulting in an authorization bypass when an administrator has explicitly configured a Protected Rule policy on one or more application resources.
Affected product and versions
Customers using the Okta Access Gateway versions prior to 2026.9.1 are affected.
This applies if the following preconditions are present:
A Protected Rule policy is actively configured on one or more application resources.
A Protected Rule policy is actively configured on one or more application resources.
An authenticated user holds a valid account assigned to the application at any privilege level.
An authenticated user holds a valid account assigned to the application at any privilege level.
Customer Recommendations
To remediate this vulnerability, upgrade Okta Access Gateway to version 2026.9.1 or greater.
The vulnerability is present in Okta Access Gateway versions prior to 2026.9.1 and is resolved in version 2026.9.1.
CWE-863 – Incorrect Authorization
Vector string: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Download the Okta Access Gateway image
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
