← back
CVE-2026-78545mediumCWE-94

Improper Input Sanitization in Okta Access Gateway Application Label Configuration

13Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 6.6epss 0.4%
exploitation probability
0.4%top 71% of all CVEs
observed exploitation
nono source reports it
The Okta Access Gateway does not sanitize the application label field before including it in the generated nginx configuration file. The unsanitized value is interpolated into an nginx server block directive, resulting in execution of injected directives.
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H