Vulnerability Details CVE-2026-78626
The Okta Access Gateway improperly handles input sanitization and regular expression evaluation within its Protected Rule authorization check, resulting in an authorization bypass when an administrator has explicitly configured a Protected Rule policy on one or more application resources.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 11.9%
CVSS Severity
CVSS v3 Score 8.1
Products affected by CVE-2026-78626
-
cpe:2.3:a:okta:access_gateway:2019.1.0
-
cpe:2.3:a:okta:access_gateway:2019.4.2
-
cpe:2.3:a:okta:access_gateway:2019.4.5
-
cpe:2.3:a:okta:access_gateway:2020.1.0
-
cpe:2.3:a:okta:access_gateway:2020.10.5
-
cpe:2.3:a:okta:access_gateway:2020.11.2
-
cpe:2.3:a:okta:access_gateway:2020.12.3
-
cpe:2.3:a:okta:access_gateway:2020.2.1
-
cpe:2.3:a:okta:access_gateway:2020.3.3
-
cpe:2.3:a:okta:access_gateway:2020.4.4
-
cpe:2.3:a:okta:access_gateway:2020.5.5
-
cpe:2.3:a:okta:access_gateway:2020.6.3
-
cpe:2.3:a:okta:access_gateway:2020.7.1
-
cpe:2.3:a:okta:access_gateway:2020.8.3
-
cpe:2.3:a:okta:access_gateway:2020.8.4
-
cpe:2.3:a:okta:access_gateway:2020.9.3
-
cpe:2.3:a:okta:access_gateway:2021.01.0
-
cpe:2.3:a:okta:access_gateway:2021.02.1
-
cpe:2.3:a:okta:access_gateway:2021.03.6
-
cpe:2.3:a:okta:access_gateway:2025.1.1
-
cpe:2.3:a:okta:access_gateway:2025.10.0
-
cpe:2.3:a:okta:access_gateway:2025.3.0
-
cpe:2.3:a:okta:access_gateway:2025.3.1
-
cpe:2.3:a:okta:access_gateway:2025.5.4
-
cpe:2.3:a:okta:access_gateway:2025.6.0
-
cpe:2.3:a:okta:access_gateway:2025.7.1
-
cpe:2.3:a:okta:access_gateway:2025.8.0
-
cpe:2.3:a:okta:access_gateway:2025.9.0
-
cpe:2.3:a:okta:access_gateway:2026.3.0
-
cpe:2.3:a:okta:access_gateway:2026.4.0
-
cpe:2.3:a:okta:access_gateway:2026.5.1
-
cpe:2.3:a:okta:access_gateway:2026.6.0
-
cpe:2.3:a:okta:access_gateway:2026.8.0