PT-2026-88428 · Okta · Okta Access Gateway

CVE-2026-78552

·

Publicado

2026-09-08

·

Atualizado

2026-09-08

CVSS v3.1

6.0

Média

VetorAV:N/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:L
The Okta Access Gateway does not apply its Lua directive restriction to the application-level custom configuration field. The field is interpolated directly into the nginx server block without inspection, resulting in execution of injected directives.

Correção

Protection Mechanism Failure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-78552

Produtos afetados

Okta Access Gateway