7.2
CVE-2026-78550
- EPSS 0.36%
- Veröffentlicht 08.09.2026 20:18:35
- Zuletzt bearbeitet 29.09.2026 20:13:02
- Erkennungen
Improper Input Handling in Okta Access Gateway Management Console Exception Handler
The Okta Access Gateway management console passes user-supplied input to eval() without sanitization during an authenticated administrator SSH session. As a result, the unsanitized input is executed directly, leading to code execution with the privileges of the management console.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Okta ≫ Access Gateway Version < 2026.9.1
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.36% | 0.289 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 7.2 | 1.2 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
|
| psirt@okta.com | 6.6 | 0.7 | 5.9 |
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
|
CWE-95 Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')
The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes code syntax before using the input in a dynamic evaluation call (e.g. "eval").
https://trust.okta.com/security-advisories/improper-input-handling-in-okta-access-gateway-management-console-exception-handler-cve-2026-78550