Vulnerability Details CVE-2026-78545
The Okta Access Gateway does not sanitize the application label field before including it in the generated nginx configuration file. The unsanitized value is interpolated into an nginx server block directive, resulting in execution of injected directives.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.005
EPSS Ranking 39.8%
CVSS Severity
CVSS v3 Score 6.6
Products affected by CVE-2026-78545
-
cpe:2.3:a:okta:access_gateway:2019.1.0
-
cpe:2.3:a:okta:access_gateway:2019.4.2
-
cpe:2.3:a:okta:access_gateway:2019.4.5
-
cpe:2.3:a:okta:access_gateway:2020.1.0
-
cpe:2.3:a:okta:access_gateway:2020.10.5
-
cpe:2.3:a:okta:access_gateway:2020.11.2
-
cpe:2.3:a:okta:access_gateway:2020.12.3
-
cpe:2.3:a:okta:access_gateway:2020.2.1
-
cpe:2.3:a:okta:access_gateway:2020.3.3
-
cpe:2.3:a:okta:access_gateway:2020.4.4
-
cpe:2.3:a:okta:access_gateway:2020.5.5
-
cpe:2.3:a:okta:access_gateway:2020.6.3
-
cpe:2.3:a:okta:access_gateway:2020.7.1
-
cpe:2.3:a:okta:access_gateway:2020.8.3
-
cpe:2.3:a:okta:access_gateway:2020.8.4
-
cpe:2.3:a:okta:access_gateway:2020.9.3
-
cpe:2.3:a:okta:access_gateway:2021.01.0
-
cpe:2.3:a:okta:access_gateway:2021.02.1
-
cpe:2.3:a:okta:access_gateway:2021.03.6
-
cpe:2.3:a:okta:access_gateway:2025.1.1
-
cpe:2.3:a:okta:access_gateway:2025.10.0
-
cpe:2.3:a:okta:access_gateway:2025.3.0
-
cpe:2.3:a:okta:access_gateway:2025.3.1
-
cpe:2.3:a:okta:access_gateway:2025.5.4
-
cpe:2.3:a:okta:access_gateway:2025.6.0
-
cpe:2.3:a:okta:access_gateway:2025.7.1
-
cpe:2.3:a:okta:access_gateway:2025.8.0
-
cpe:2.3:a:okta:access_gateway:2025.9.0
-
cpe:2.3:a:okta:access_gateway:2026.3.0
-
cpe:2.3:a:okta:access_gateway:2026.4.0
-
cpe:2.3:a:okta:access_gateway:2026.5.1
-
cpe:2.3:a:okta:access_gateway:2026.6.0
-
cpe:2.3:a:okta:access_gateway:2026.8.0