The Okta Access Gateway does not apply its Lua directive restriction to the application-level custom configuration field. The field is interpolated directly into the nginx server block without inspection, resulting in execution of injected directives.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-09-08 20:18
Updated : 2026-09-10 18:18
NVD link : CVE-2026-78552
Mitre link : CVE-2026-78552
CVE.ORG link : CVE-2026-78552
JSON object : View
Products Affected
No product.
CWE
CWE-693
Protection Mechanism Failure
