External risk intelligence

Okta Access Gateway SQL Injection via SAML Assertions

CVE advisorySeverity: CRITICAL (CVSS 9.9)

CVE-2026-78623

Okta Access Gateway is an edge security product designed specifically to act as an internet-facing gateway and identity portal. Its primary function is to manage external authentication and proxy traffic for backend applications, making it public-facing by design in normal deployments.

SQL Injection

Okta Access Gateway

before 2026.9.1

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory concerns a critical vulnerability in Okta Access Gateway, specifically affecting its advanced mode datastore configuration. The issue involves the improper handling of security assertion data, which could allow for unauthorized database manipulation. The main concern is confirming relevance and exposure within your Okta Access Gateway deployments.

  • Unsanitized data can lead to database compromise.
  • It's an edge security product, public-facing by design.
  • Confirm if your advanced datastore configuration is affected.

Attack Path

How an attacker could exploit the issue

An attacker with limited access could target the Okta Access Gateway by sending crafted SAML assertions. When the gateway is configured in advanced mode and uses the datastore feature, it fails to properly handle these assertions. This allows the attacker to inject malicious SQL commands, potentially leading to significant data compromise and system control.

  • Requires low-privileged access.
  • Unsanitized SAML assertions trigger vulnerability.
  • Leads to SQL injection and data compromise.

Live Threat

Current exploitation, exposure, and threat context

When Okta Access Gateway is configured in advanced mode with datastore integration, it may allow an attacker to execute arbitrary SQL commands against the backend database by sending a crafted SAML assertion. This could expose sensitive information stored within the database or disrupt service operations.

  • Database information may be exposed.
  • Unsanitized SAML assertions could be exploited.
  • Unauthorized data access or service disruption.

Operational Fix

Recommended remediation, mitigation, and detection steps

Okta Access Gateway's SQL injection vulnerability likely falls under the purview of infrastructure or platform teams managing the gateway, with potential involvement from network and security teams for exposure assessment and vendor management for Okta coordination. The immediate priority is to confirm the deployment's reachability and business criticality, identify the system owner, and plan remediation with Okta based on assessed risk.

  • Own by infrastructure or platform teams.
  • Verify external reachability and business impact.
  • Coordinate with Okta for patch or mitigation.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Okta Access Gateway?

Okta Access Gateway is an edge security solution that bridges on-premises applications with modern identity management. Organizations use it as a portal to handle authentication and proxy traffic, allowing users to securely access legacy web applications by acting as an intermediary between the user and backend systems.

How does CVE-2026-78623 work?

This vulnerability is an instance of SQL Injection (CWE-89). It occurs because the gateway fails to clean data received from SAML assertions before inserting it into database queries. By including malicious SQL commands within these assertions, an attacker can manipulate the underlying database instead of just providing identity information.

Do I need to be an admin to trigger CVE-2026-78623?

No, you do not need administrative access. The flaw is triggered by sending crafted SAML assertions to the gateway. Note that this vulnerability only applies when the system is specifically configured to use the advanced mode datastore feature; standard configurations that do not utilize this specific datastore setup are not affected.

Is my Okta Access Gateway at risk?

According to Halo Surface Signal, this software is designed as an internet-facing gateway, making it inherently reachable from the outside. Because the product's primary role is managing public-facing identity traffic, any instance using the vulnerable advanced datastore configuration should be considered exposed to network-based attacks.

When should I prioritize fixing this?

You should prioritize this immediately if you use advanced mode datastores. Start by identifying your infrastructure team to verify if this specific feature is active in your environment. Once confirmed, coordinate with your technical leads to apply the vendor-provided updates to move beyond the affected version range.

References