VYPR
Medium severity6.6NVD Advisory· Published Sep 8, 2026· Updated Sep 8, 2026

CVE-2026-78545

CVE-2026-78545

Description

The Okta Access Gateway does not sanitize the application label field before including it in the generated nginx configuration file. The unsanitized value is interpolated into an nginx server block directive, resulting in execution of injected directives.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

1

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.