Skip to content
Okta Patches Critical Vulnerabilities Enabling XSS, Auth Bypass, and SQL Injection

Okta Patches Critical Vulnerabilities Enabling XSS, Auth Bypass, and SQL Injection

First seen 11 Sep 2026, 12:46 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 11, 2026 at 23:29 UTC
  • Three critical vulnerabilities in Okta's Auth0 and Access Gateway were disclosed on September 8, 2026.
  • CVE-2026-85982 enables stored XSS with a CVSS score of 9.0, affecting Auth0 AD/LDAP Connector.
  • Organizations must upgrade to versions 8.0.0 and 2026.9.1 or later to remediate these vulnerabilities.

Okta has issued security updates for three critical vulnerabilities affecting the Auth0 AD/LDAP Connector and Okta Access Gateway. These vulnerabilities, disclosed on September 8, 2026, could allow authenticated attackers to execute stored cross-site scripting (XSS), bypass Protected Rule authorization, and perform unintended SQL commands. The most severe issue, CVE-2026-85982, has a CVSS score of 9.0 and affects Auth0 AD/LDAP Connector versions prior to 8.0.0. CVE-2026-78626, with a CVSS score of 8.1, allows authorization bypass in Okta Access Gateway versions before 2026.9.1. Additionally, CVE-2026-78623 enables SQL injection through unsanitized SAML assertion values in the same Access Gateway versions. Organizations using these components should prioritize upgrading to the latest versions to mitigate risks.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-08
Vulnerabilities disclosed
Okta disclosed three critical vulnerabilities affecting Auth0 AD/LDAP Connector and Access Gateway.
Gbhackers
2026-09-08
CVE-2026-78623 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-08
CVE-2026-85982 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-08
CVE-2026-78626 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-11
Security updates released
Okta released patches for the vulnerabilities, urging organizations to upgrade immediately.
Gbhackers

More articles in this cluster (6)

Following this threat?

Track Okta and CVE-2026-78623 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed