Skip to content

CVE-2026-78626

trust.okta.com September 11, 2026

The Okta Access Gateway improperly handles input sanitization and regular expression evaluation within its Protected Rule authorization check, resulting in an authorization bypass when an administrator has explicitly configured a Protected Rule policy on one or more application resources.

Affected product and versions

Customers using the Okta Access Gateway versions prior to 2026.9.1 are affected.

This applies if the following preconditions are present:

A Protected Rule policy is actively configured on one or more application resources.

A Protected Rule policy is actively configured on one or more application resources.

An authenticated user holds a valid account assigned to the application at any privilege level.

An authenticated user holds a valid account assigned to the application at any privilege level.

Customer Recommendations

To remediate this vulnerability, upgrade Okta Access Gateway to version 2026.9.1 or greater.

The vulnerability is present in Okta Access Gateway versions prior to 2026.9.1 and is resolved in version 2026.9.1.

CWE-863 – Incorrect Authorization

Vector string: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

Download the Okta Access Gateway image

Extracted Entities