Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2026-78626

The Okta Access Gateway improperly handles input sanitization and regular expression evaluation within its Protected Rule authorization check, resulting in an authorization bypass when an administrator has explicitly configured a Protected Rule policy on one or more application resources.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 11.9%
CVSS Severity
CVSS v3 Score 8.1
Products affected by CVE-2026-78626


Contact Us

Shodan ® - All rights reserved