VendorsOktaaccess_gatewayany version
Vulnerabilities

Okta Access Gateway any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

10CVEs
CVE-2026-78623
Improper Handling of SAML Assertion Attributes in Okta Access Gateway Advanced Mode Datastores
Published 2026-09-08 · Analyzed
9.9EPSS 0.005
CVE-2021-28113
A command injection vulnerability in the cookieDomain and relayDomain parameters of Okta Access Gateway before 2020.9.3 allows attackers (with admin access to the Okta Access Gateway UI) to execute OS commands as a privileged system account.
Published 2021-04-02 · Modified
8.7EPSS 0.223
CVE-2026-78626
Improper Input Sanitization in Okta Access Gateway Protected Rules
Published 2026-09-08 · Analyzed
8.1EPSS 0.004
CVE-2026-78579
Improper Input Sanitization in Okta Access Gateway LDAP Datastore Filter Interpolation
Published 2026-09-08 · Analyzed
6.8EPSS 0.002
CVE-2026-78625
Insufficient Validation of Dashboard Application Labels in Okta Access Gateway Dashboard Site Configuration
Published 2026-09-08 · Analyzed
6.7EPSS 0.002
CVE-2026-78630
Improper Input Neutralization in Okta Access Gateway SNMP Configuration Processing
Published 2026-09-08 · Analyzed
6.7EPSS 0.002
CVE-2026-78560
Improper Authentication Validation in Okta Access Gateway Pass-Through Authentication Source
Published 2026-09-08 · Analyzed
6.5EPSS 0.002
CVE-2026-78552
Validation Bypass in Okta Access Gateway Custom Directives
Published 2026-09-08 · Analyzed
6.0EPSS 0.003
CVE-2026-78620
Improper Path Validation in Okta Access Gateway Kerberos Configuration Handling
Published 2026-09-08 · Analyzed
5.9EPSS 0.003
CVE-2026-78624
Improper Path Validation in Okta Access Gateway Backup and Restore Functionality
Published 2026-09-08 · Analyzed
4.9EPSS 0.005