MEDIUM 6.6 NVD
CVE-2026-78545
The Okta Access Gateway does not sanitize the application label field before including it in the generated nginx configuration file. The unsanitized value is in
The Okta Access Gateway does not sanitize the application label field before including it in the generated nginx configuration file. The unsanitized value is interpolated into an nginx server block directive, resulting in execution of injected directives.
References
This medium severity vulnerability with a CVSS score of 6.6 was published on 2026-09-08 via NVD.
vulnfeed aggregates 13138 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.