CVE-2026-78550

medium

Description

The Okta Access Gateway management console passes user-supplied input to eval() without sanitization during an authenticated administrator SSH session. As a result, the unsanitized input is executed directly, leading to code execution with the privileges of the management console.

References

https://trust.okta.com/security-advisories/improper-input-handling-in-okta-access-gateway-management-console-exception-handler-cve-2026-78550

Details

Source: Mitre, NVD

Published: 2026-09-08

Updated: 2026-09-10

Risk Information

CVSS v2

Base Score: 6.8

Vector: CVSS2#AV:N/AC:H/Au:M/C:C/I:C/A:C

Severity: Medium

CVSS v3

Base Score: 6.6

Vector: CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H

Severity: Medium

EPSS

EPSS: 0.00357