Gbhackers Okta Patches Critical Vulnerabilities Enabling XSS, Auth Bypass, and SQL Injection
Article Content
- •Three critical vulnerabilities in Okta's Auth0 and Access Gateway were disclosed on September 8, 2026.
- •CVE-2026-85982 enables stored XSS with a CVSS score of 9.0, affecting Auth0 AD/LDAP Connector.
- •Organizations must upgrade to versions 8.0.0 and 2026.9.1 or later to remediate these vulnerabilities.
Okta has issued security updates for three critical vulnerabilities affecting the Auth0 AD/LDAP Connector and Okta Access Gateway. These vulnerabilities, disclosed on September 8, 2026, could allow authenticated attackers to execute stored cross-site scripting (XSS), bypass Protected Rule authorization, and perform unintended SQL commands. The most severe issue, CVE-2026-85982, has a CVSS score of 9.0 and affects Auth0 AD/LDAP Connector versions prior to 8.0.0. CVE-2026-78626, with a CVSS score of 8.1, allows authorization bypass in Okta Access Gateway versions before 2026.9.1. Additionally, CVE-2026-78623 enables SQL injection through unsanitized SAML assertion values in the same Access Gateway versions. Organizations using these components should prioritize upgrading to the latest versions to mitigate risks.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (6)
Following this threat?
Track Okta and CVE-2026-78623 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
KATARU IoT Malware Exploits Linux Vulnerabilities for DDoS Attacks The KATARU malware targets internet-exposed IoT devices using Telnet credential brute-forcing. Once access is gained, it attempts to escalate privileges using public Linux exploits, including CVE-2026-46300, CVE-2026-43284, and CVE-2026-31431. The malware combines Mirai-style DDoS capabilities with encrypted…
Critical CSF Vulnerability Allows Remote Code Execution A critical vulnerability in ConfigServer Security & Firewall (CSF), tracked as CVE-2026-65638, was disclosed on September 10, 2026. This flaw affects CSF versions 14.00 through 16.29, allowing unauthenticated remote attackers to execute arbitrary commands via the MESSENGER service. Administrators are urged to upgrade…