Skip to content

Okta Fixes Auth0 and Access Gateway Flaws Enabling XSS, Auth Bypass, and SQL Injection

Cybersecuritynews Abinaya September 11, 2026

Okta has released security fixes for three vulnerabilities affecting the Auth0 AD/LDAP Connector and Okta Access Gateway. The flaws could enable stored cross-site scripting, authorization bypass, and SQL injection in certain configurations. The vulnerabilities were disclosed on September 8, 2026. Organizations using the affected identity and access management components should prioritize upgrades, especially where Access […]