High severity7.7NVD Advisory· Published Sep 8, 2026· Updated Sep 8, 2026
CVE-2026-78623
CVE-2026-78623
Description
The Okta Access Gateway does not sanitize SAML assertion values before interpolating them into database queries in the advanced mode datastore configuration. The unsanitized values are substituted directly into the query string prior to preparation, resulting in unintended SQL execution against the configured backend database.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2(expand)+ 1 more
- (no CPE)
- (no CPE)
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.