Medium severity6.7NVD Advisory· Published Apr 2, 2021· Updated Jun 17, 2026
CVE-2021-28113
CVE-2021-28113
Description
A command injection vulnerability in the cookieDomain and relayDomain parameters of Okta Access Gateway before 2020.9.3 allows attackers (with admin access to the Okta Access Gateway UI) to execute OS commands as a privileged system account.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:okta:access_gateway:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:okta:access_gateway:*:*:*:*:*:*:*:*range: <=2020.8.4
- (no CPE)range: <2020.9.3
- Okta/Access Gatewaydescription
Patches
Vulnerability mechanics
References
2- packetstormsecurity.com/files/163428/Okta-Access-Gateway-2020.5.5-Authenticated-Remote-Root.htmlnvdExploitThird Party AdvisoryVDB Entry
- www.okta.com/security-advisories/cve-2021-28113nvdVendor Advisory
News mentions
0No linked articles in our index yet.