MEDIUMVulnerability

CVE-2026-78545

The Okta Access Gateway does not sanitize the application label field before including it in the generated nginx configuration file. The unsanitized value is interpolated into an nginx server block directive, resulting in execution of injected directives.

Properties

severity
MEDIUM
score
6.6
cve_id
CVE-2026-78545
signal_observed_at
2026-09-17T13:49:22+00:00
vector
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
published_at
2026-09-08T20:18:35.727
last_modified
2026-09-10T19:17:34.710

Related Entities (2)

HAS_WEAKNESS (1)

[Weakness]Improper Control of Generation of Code ('Code Injection')

DESCRIBED_BY (1)

[Source]NVD

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-78545 — Ninja Signal Threat Intelligence | Ninja Signal