Back

MEDIUM

Validation Bypass in Okta Access Gateway Custom Directives

Published Sep 8, 2026

Description

The Okta Access Gateway does not apply its Lua directive restriction to the application-level custom configuration field. The field is interpolated directly into the nginx server block without inspection, resulting in execution of injected directives.

Affected products

Remediation

Vendor solution

Upgrade the Okta Access Gateway appliance to version 2026.9.1 or greater.

Metrics

Weaknesses (1)

References (1)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Okta
Published Sep 8, 2026
Updated Sep 10, 2026
Reserved Aug 24, 2026
CISA Vulnrichment
Updated Sep 10, 2026
NVD
Status Undergoing Analysis
Modified Sep 10, 2026
Red Hat
Severity n/a
Public date n/a