MEDIUMVulnerability

CVE-2026-78625

The Okta Access Gateway does not sanitize dashboard label values before writing them into generated PHP configuration files. The generated file is automatically included during authentication requests, resulting in execution with the privileges of the web server process.

Properties

severity
MEDIUM
score
6.7
cve_id
CVE-2026-78625
signal_observed_at
2026-09-23T04:35:38+00:00
vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
published_at
2026-09-08T20:18:37.647
last_modified
2026-09-22T20:16:41.267

Related Entities (3)

HAS_WEAKNESS (1)

[Weakness]Improper Control of Generation of Code ('Code Injection')

DESCRIBED_BY (1)

[Source]NVD

AFFECTS_PRODUCT (1)

[Product]

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-78625 — Ninja Signal Threat Intelligence | Ninja Signal