{"api_version":"1","generated_at":"2026-09-10T23:53:43+00:00","cve":"CVE-2026-78625","urls":{"html":"https://cve.report/CVE-2026-78625","api":"https://cve.report/api/cve/CVE-2026-78625.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-78625","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-78625"},"summary":{"title":"Insufficient Validation of Dashboard Application Labels in Okta Access Gateway Dashboard Site Configuration","description":"The Okta Access Gateway does not sanitize dashboard label values before writing them into generated PHP configuration files. The generated file is automatically included during authentication requests, resulting in execution with the privileges of the web server process.","state":"PUBLISHED","assigner":"Okta","published_at":"2026-09-08 20:18:37","updated_at":"2026-09-10 15:17:42"},"problem_types":["CWE-94","CWE-94 Improper Control of Generation of Code"],"metrics":[{"version":"3.1","source":"psirt@okta.com","type":"Secondary","score":"6.7","severity":"MEDIUM","vector":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","baseScore":6.7,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"}},{"version":"3.1","source":"CNA","type":"DECLARED","score":"6.7","severity":"MEDIUM","vector":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","data":{"attackComplexity":"LOW","attackVector":"LOCAL","availabilityImpact":"HIGH","baseScore":6.7,"baseSeverity":"MEDIUM","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"HIGH","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","version":"3.1"}}],"references":[{"url":"https://trust.okta.com/security-advisories/insufficient-validation-of-dashboard-application-labels-in-okta-access-gateway-dashboard-site-configuration-cve-2026-78625","name":"https://trust.okta.com/security-advisories/insufficient-validation-of-dashboard-application-labels-in-okta-access-gateway-dashboard-site-configuration-cve-2026-78625","refsource":"psirt@okta.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-78625","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-78625","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Okta","product":"Okta Access Gateway","version":"affected 2026.9.1 semver","platforms":[]}],"timeline":[],"solutions":[{"source":"CNA","title":"","value":"Upgrade Okta Access Gateway to version 2026.9.1 or greater.","time":"","lang":"en"}],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"metrics":[{"other":{"content":{"id":"CVE-2026-78625","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"total"}],"role":"CISA Coordinator","timestamp":"2026-09-10T14:34:46.618350Z","version":"2.0.3"},"type":"ssvc"}}],"providerMetadata":{"dateUpdated":"2026-09-10T14:34:56.113Z","orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP"},"title":"CISA ADP Vulnrichment"}],"cna":{"affected":[{"defaultStatus":"unaffected","product":"Okta Access Gateway","vendor":"Okta","versions":[{"lessThan":"2026.9.1","status":"affected","version":"0","versionType":"semver"}]}],"descriptions":[{"lang":"en","value":"The Okta Access Gateway does not sanitize dashboard label values before writing them into generated PHP configuration files. The generated file is automatically included during authentication requests, resulting in execution with the privileges of the web server process."}],"metrics":[{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"LOCAL","availabilityImpact":"HIGH","baseScore":6.7,"baseSeverity":"MEDIUM","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"HIGH","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","version":"3.1"}}],"problemTypes":[{"descriptions":[{"cweId":"CWE-94","description":"Improper Control of Generation of Code","lang":"en"}]}],"providerMetadata":{"dateUpdated":"2026-09-08T20:10:43.387Z","orgId":"59b22baa-87b2-4371-8e4a-e080df12f74a","shortName":"Okta"},"references":[{"url":"https://trust.okta.com/security-advisories/insufficient-validation-of-dashboard-application-labels-in-okta-access-gateway-dashboard-site-configuration-cve-2026-78625"}],"solutions":[{"lang":"en","value":"Upgrade Okta Access Gateway to version 2026.9.1 or greater."}],"title":"Insufficient Validation of Dashboard Application Labels in Okta Access Gateway Dashboard Site Configuration"}},"cveMetadata":{"assignerOrgId":"59b22baa-87b2-4371-8e4a-e080df12f74a","assignerShortName":"Okta","cveId":"CVE-2026-78625","datePublished":"2026-09-08T20:10:43.387Z","dateReserved":"2026-08-24T22:04:00.475Z","dateUpdated":"2026-09-10T14:34:56.113Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-09-08 20:18:37","lastModifiedDate":"2026-09-10 15:17:42","problem_types":["CWE-94","CWE-94 Improper Control of Generation of Code"],"metrics":{"cvssMetricV31":[{"source":"psirt@okta.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","baseScore":6.7,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":0.8,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-09-10T14:34:46.618350Z","id":"CVE-2026-78625","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"78625","Ordinal":"1","Title":"Insufficient Validation of Dashboard Application Labels in Okta ","CVE":"CVE-2026-78625","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"78625","Ordinal":"1","NoteData":"The Okta Access Gateway does not sanitize dashboard label values before writing them into generated PHP configuration files. The generated file is automatically included during authentication requests, resulting in execution with the privileges of the web server process.","Type":"Description","Title":"Insufficient Validation of Dashboard Application Labels in Okta "}]}}}