GHSA-4vpp-8gg6-2rvhHighCVSS 8.1

The Okta Access Gateway improperly handles input sanitization and regular expression evaluation...

Published
September 8, 2026
Last Modified
September 8, 2026

🔗 CVE IDs covered (1)

📋 Description

The Okta Access Gateway improperly handles input sanitization and regular expression evaluation within its Protected Rule authorization check, resulting in an authorization bypass when an administrator has explicitly configured a Protected Rule policy on one or more application resources.

🔗 References (3)