MEDIUMVulnerability

CVE-2026-78620

The Okta Access Gateway Kerberos configuration handler does not validate file paths specified in event payloads before writing file contents. The path from the event payload is used directly as the write destination, resulting in files being written to unintended locations on the appliance filesystem.

Properties

severity
MEDIUM
score
5.9
cve_id
CVE-2026-78620
signal_observed_at
2026-09-23T04:35:38+00:00
vector
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N
published_at
2026-09-08T20:18:36.777
last_modified
2026-09-22T20:39:20.293

Related Entities (3)

HAS_WEAKNESS (1)

[Weakness]External Control of File Name or Path

DESCRIBED_BY (1)

[Source]NVD

AFFECTS_PRODUCT (1)

[Product]

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-78620 — Ninja Signal Threat Intelligence | Ninja Signal