The Okta Access Gateway does not sanitize dashboard label values before writing them into generated PHP configuration files. The generated file is automatically included during authentication requests, resulting in execution with the privileges of the web server process.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-09-08 20:18
Updated : 2026-09-10 15:17
NVD link : CVE-2026-78625
Mitre link : CVE-2026-78625
CVE.ORG link : CVE-2026-78625
JSON object : View
Products Affected
No product.
CWE
CWE-94
Improper Control of Generation of Code ('Code Injection')
