CVE-2026-78550
EUVD-2026-7416408.09.2026, 20:18
The Okta Access Gateway management console passes user-supplied input to eval() without sanitization during an authenticated administrator SSH session. As a result, the unsanitized input is executed directly, leading to code execution with the privileges of the management console.
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| okta | access_gateway | 𝑥 < 2026.9.1 | CNA |