CVE-2026-78624

The Okta Access Gateway backup restore function does not validate the filename embedded in an encrypted backup payload. This results in writing file contents to unintended locations on the appliance filesystem.
Configurations

No configuration.

History

No history.

Information

Published : 2026-09-08 20:18

Updated : 2026-09-10 15:17


NVD link : CVE-2026-78624

Mitre link : CVE-2026-78624

CVE.ORG link : CVE-2026-78624


JSON object : View

Products Affected

No product.

CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')