logo

Okta Fixes Auth0 and Access Gateway Flaws Enabling XSS, Auth Bypass, and SQL Injection

ID: a3394542-c057-5bd1-a1a2-dcd1f32213e7

STIX ID: report--a3394542-c057-5bd1-a1a2-dcd1f32213e7

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2026-09-11

Date Updated: 2026-09-11

Author: Abinaya

...
...

Okta released fixes for three high-severity vulnerabilities affecting the Auth0 AD/LDAP Connector and Okta Access Gateway: CVE-2026-85982 (stored XSS, CVSS 9.0) that can execute in an admin’s browser via directory/search-result or log data, CVE-2026-78626 (authorization bypass, CVSS 8.1) in Protected Rules allowing authenticated low-privilege users to access restricted resources, and CVE-2026-78623 (SQL injection, CVSS 7.7) in advanced-mode datastores when SAML attributes are interpolated into custom queries; organizations should prioritize upgrades (auth0/ad-ldap-connector >= 8.0.0 and Access Gateway >= 2026.9.1), review Protected Rule configurations, audit custom queries using SAML attributes, and inspect directory permissions and connector logs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.