CVE-2026-78552
EUVD-2026-7416808.09.2026, 20:18
The Okta Access Gateway does not apply its Lua directive restriction to the application-level custom configuration field. The field is interpolated directly into the nginx server block without inspection, resulting in execution of injected directives.Enginsight
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| okta | access_gateway | 𝑥 < 2026.9.1 | CNA |
Common Weakness Enumeration