Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Upgrade the Okta Access Gateway appliance to version 2026.9.1 or greater.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 08 Sep 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Okta Access Gateway does not sanitize SAML assertion attribute values before interpolating them into LDAP search filters in the LDAP datastore configuration. The raw values are substituted directly into the filter string and passed to the LDAP search operation, resulting in modification of the intended query logic. | |
| Title | Improper Input Sanitization in Okta Access Gateway LDAP Datastore Filter Interpolation | |
| Weaknesses | CWE-90 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: Okta
Published:
Updated: 2026-09-08T20:12:53.558Z
Reserved: 2026-08-24T20:50:31.443Z
Link: CVE-2026-78579
No data.
Status : Awaiting Analysis
Published: 2026-09-08T20:18:36.590
Modified: 2026-09-08T21:13:32.293
Link: CVE-2026-78579
No data.
OpenCVE Enrichment
No data.
-
CWE-90
Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection')