Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2026-78545

The Okta Access Gateway does not sanitize the application label field before including it in the generated nginx configuration file. The unsanitized value is interpolated into an nginx server block directive, resulting in execution of injected directives.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.004
EPSS Ranking 29.5%
CVSS Severity
CVSS v3 Score 6.6


Contact Us

Shodan ® - All rights reserved