Okta Fixes Auth0 and Access Gateway Flaws Enabling XSS, Auth Bypass, and SQL Injection
Okta has released security fixes for three vulnerabilities affecting the Auth0 AD/LDAP Connector and Okta Access Gateway. The flaws could enable stored cross-site scripting, authorization bypass, and SQL injection in certain configurations. The vulnerabilities were disclosed on September 8, 2026. Organizations using the affected identity and access management components should prioritize upgrades, especially where Access […]
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
