{"api_version":"1","generated_at":"2026-09-11T21:09:44+00:00","cve":"CVE-2026-78545","urls":{"html":"https://cve.report/CVE-2026-78545","api":"https://cve.report/api/cve/CVE-2026-78545.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-78545","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-78545"},"summary":{"title":"Improper Input Sanitization in Okta Access Gateway Application Label Configuration","description":"The Okta Access Gateway does not sanitize the application label field before including it in the generated nginx configuration file. The unsanitized value is interpolated into an nginx server block directive, resulting in execution of injected directives.","state":"PUBLISHED","assigner":"Okta","published_at":"2026-09-08 20:18:35","updated_at":"2026-09-10 19:17:34"},"problem_types":["CWE-94","CWE-94 Improper Control of Generation of Code"],"metrics":[{"version":"3.1","source":"psirt@okta.com","type":"Secondary","score":"6.6","severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H","baseScore":6.6,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"}},{"version":"3.1","source":"CNA","type":"DECLARED","score":"6.6","severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H","data":{"attackComplexity":"HIGH","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":6.6,"baseSeverity":"MEDIUM","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"HIGH","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H","version":"3.1"}}],"references":[{"url":"https://trust.okta.com/security-advisories/improper-input-sanitization-in-okta-access-gateway-application-label-configuration-cve-2026-78545/","name":"https://trust.okta.com/security-advisories/improper-input-sanitization-in-okta-access-gateway-application-label-configuration-cve-2026-78545/","refsource":"psirt@okta.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-78545","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-78545","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Okta","product":"Okta Access Gateway","version":"affected 2026.9.1 semver","platforms":[]}],"timeline":[],"solutions":[{"source":"CNA","title":"","value":"Upgrade the Okta Access Gateway appliance to version 2026.9.1 or greater.","time":"","lang":"en"}],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2026","cve_id":"78545","cve":"CVE-2026-78545","epss":"0.003570000","percentile":"0.289360000","score_date":"2026-09-10","updated_at":"2026-09-11 00:05:15"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"metrics":[{"other":{"content":{"id":"CVE-2026-78545","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"total"}],"role":"CISA Coordinator","timestamp":"2026-09-10T18:00:45.406892Z","version":"2.0.3"},"type":"ssvc"}}],"providerMetadata":{"dateUpdated":"2026-09-10T18:01:32.244Z","orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP"},"title":"CISA ADP Vulnrichment"}],"cna":{"affected":[{"defaultStatus":"unaffected","product":"Okta Access Gateway","vendor":"Okta","versions":[{"lessThan":"2026.9.1","status":"affected","version":"0","versionType":"semver"}]}],"descriptions":[{"lang":"en","value":"The Okta Access Gateway does not sanitize the application label field before including it in the generated nginx configuration file. The unsanitized value is interpolated into an nginx server block directive, resulting in execution of injected directives."}],"metrics":[{"cvssV3_1":{"attackComplexity":"HIGH","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":6.6,"baseSeverity":"MEDIUM","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"HIGH","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H","version":"3.1"}}],"problemTypes":[{"descriptions":[{"cweId":"CWE-94","description":"Improper Control of Generation of Code","lang":"en"}]}],"providerMetadata":{"dateUpdated":"2026-09-08T20:05:36.216Z","orgId":"59b22baa-87b2-4371-8e4a-e080df12f74a","shortName":"Okta"},"references":[{"url":"https://trust.okta.com/security-advisories/improper-input-sanitization-in-okta-access-gateway-application-label-configuration-cve-2026-78545/"}],"solutions":[{"lang":"en","value":"Upgrade the Okta Access Gateway appliance to version 2026.9.1 or greater."}],"title":"Improper Input Sanitization in Okta Access Gateway Application Label Configuration"}},"cveMetadata":{"assignerOrgId":"59b22baa-87b2-4371-8e4a-e080df12f74a","assignerShortName":"Okta","cveId":"CVE-2026-78545","datePublished":"2026-09-08T20:05:36.216Z","dateReserved":"2026-08-24T18:44:02.108Z","dateUpdated":"2026-09-10T18:01:32.244Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-09-08 20:18:35","lastModifiedDate":"2026-09-10 19:17:34","problem_types":["CWE-94","CWE-94 Improper Control of Generation of Code"],"metrics":{"cvssMetricV31":[{"source":"psirt@okta.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H","baseScore":6.6,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":0.7,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-09-10T18:00:45.406892Z","id":"CVE-2026-78545","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"78545","Ordinal":"1","Title":"Improper Input Sanitization in Okta Access Gateway Application L","CVE":"CVE-2026-78545","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"78545","Ordinal":"1","NoteData":"The Okta Access Gateway does not sanitize the application label field before including it in the generated nginx configuration file. The unsanitized value is interpolated into an nginx server block directive, resulting in execution of injected directives.","Type":"Description","Title":"Improper Input Sanitization in Okta Access Gateway Application L"}]}}}