{"api_version":"1","generated_at":"2026-09-11T00:21:18+00:00","cve":"CVE-2026-78560","urls":{"html":"https://cve.report/CVE-2026-78560","api":"https://cve.report/api/cve/CVE-2026-78560.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-78560","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-78560"},"summary":{"title":"Improper Authentication Validation in Okta Access Gateway Pass-Through Authentication Source","description":"The Okta Access Gateway includes an optional pass-through authentication source that accepts user identity from a client-supplied HTTP header without cryptographic validation. In architectures where this optional source is enabled without an upstream reverse proxy or firewall configured to sanitize and enforce client headers, an unauthenticated user can supply an arbitrary identity value to initiate a session.","state":"PUBLISHED","assigner":"Okta","published_at":"2026-09-08 20:18:36","updated_at":"2026-09-10 15:17:41"},"problem_types":["CWE-287","CWE-287 Improper Authentication"],"metrics":[{"version":"3.1","source":"psirt@okta.com","type":"Secondary","score":"4.8","severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N","baseScore":4.8,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"}},{"version":"3.1","source":"CNA","type":"DECLARED","score":"4.8","severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N","data":{"attackComplexity":"HIGH","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":4.8,"baseSeverity":"MEDIUM","confidentialityImpact":"LOW","integrityImpact":"LOW","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N","version":"3.1"}}],"references":[{"url":"https://trust.okta.com/security-advisories/improper-authentication-validation-in-okta-access-gateway-pass-through-authentication-source-cve-2026-78560","name":"https://trust.okta.com/security-advisories/improper-authentication-validation-in-okta-access-gateway-pass-through-authentication-source-cve-2026-78560","refsource":"psirt@okta.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-78560","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-78560","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Okta","product":"Okta Access Gateway","version":"affected 2026.9.1 semver","platforms":[]}],"timeline":[],"solutions":[{"source":"CNA","title":"","value":"Upgrade the Okta Access Gateway appliance to version 2026.9.1 or greater.","time":"","lang":"en"}],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2026","cve_id":"78560","cve":"CVE-2026-78560","epss":"0.002010000","percentile":"0.099870000","score_date":"2026-09-10","updated_at":"2026-09-11 00:05:16"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"metrics":[{"other":{"content":{"id":"CVE-2026-78560","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","timestamp":"2026-09-10T14:30:48.218255Z","version":"2.0.3"},"type":"ssvc"}}],"providerMetadata":{"dateUpdated":"2026-09-10T14:30:58.493Z","orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP"},"title":"CISA ADP Vulnrichment"}],"cna":{"affected":[{"defaultStatus":"unaffected","product":"Okta Access Gateway","vendor":"Okta","versions":[{"lessThan":"2026.9.1","status":"affected","version":"0","versionType":"semver"}]}],"descriptions":[{"lang":"en","value":"The Okta Access Gateway includes an optional pass-through authentication source that accepts user identity from a client-supplied HTTP header without cryptographic validation. In architectures where this optional source is enabled without an upstream reverse proxy or firewall configured to sanitize and enforce client headers, an unauthenticated user can supply an arbitrary identity value to initiate a session."}],"metrics":[{"cvssV3_1":{"attackComplexity":"HIGH","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":4.8,"baseSeverity":"MEDIUM","confidentialityImpact":"LOW","integrityImpact":"LOW","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N","version":"3.1"}}],"problemTypes":[{"descriptions":[{"cweId":"CWE-287","description":"Improper Authentication","lang":"en"}]}],"providerMetadata":{"dateUpdated":"2026-09-08T20:09:46.636Z","orgId":"59b22baa-87b2-4371-8e4a-e080df12f74a","shortName":"Okta"},"references":[{"url":"https://trust.okta.com/security-advisories/improper-authentication-validation-in-okta-access-gateway-pass-through-authentication-source-cve-2026-78560"}],"solutions":[{"lang":"en","value":"Upgrade the Okta Access Gateway appliance to version 2026.9.1 or greater."}],"title":"Improper Authentication Validation in Okta Access Gateway Pass-Through Authentication Source"}},"cveMetadata":{"assignerOrgId":"59b22baa-87b2-4371-8e4a-e080df12f74a","assignerShortName":"Okta","cveId":"CVE-2026-78560","datePublished":"2026-09-08T20:09:46.636Z","dateReserved":"2026-08-24T20:01:42.878Z","dateUpdated":"2026-09-10T14:30:58.493Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-09-08 20:18:36","lastModifiedDate":"2026-09-10 15:17:41","problem_types":["CWE-287","CWE-287 Improper Authentication"],"metrics":{"cvssMetricV31":[{"source":"psirt@okta.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N","baseScore":4.8,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.2,"impactScore":2.5}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-09-10T14:30:48.218255Z","id":"CVE-2026-78560","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"78560","Ordinal":"1","Title":"Improper Authentication Validation in Okta Access Gateway Pass-T","CVE":"CVE-2026-78560","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"78560","Ordinal":"1","NoteData":"The Okta Access Gateway includes an optional pass-through authentication source that accepts user identity from a client-supplied HTTP header without cryptographic validation. In architectures where this optional source is enabled without an upstream reverse proxy or firewall configured to sanitize and enforce client headers, an unauthenticated user can supply an arbitrary identity value to initiate a session.","Type":"Description","Title":"Improper Authentication Validation in Okta Access Gateway Pass-T"}]}}}