MEDIUMVulnerability

CVE-2026-78624

The Okta Access Gateway backup restore function does not validate the filename embedded in an encrypted backup payload. This results in writing file contents to unintended locations on the appliance filesystem.

Properties

severity
MEDIUM
score
4.9
cve_id
CVE-2026-78624
signal_observed_at
2026-09-23T04:35:38+00:00
vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
published_at
2026-09-08T20:18:37.397
last_modified
2026-09-22T20:19:15.390

Related Entities (3)

HAS_WEAKNESS (1)

[Weakness]Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

DESCRIBED_BY (1)

[Source]NVD

AFFECTS_PRODUCT (1)

[Product]

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-78624 — Ninja Signal Threat Intelligence | Ninja Signal