Okta Patches Auth0 and Access Gateway Vulnerabilities Let Attackers Enable XSS, Authentication Bypass and SQL Injection
ID: bb0d8c23-3e1b-5ac7-bc49-af61417a7624
STIX ID: report--bb0d8c23-3e1b-5ac7-bc49-af61417a7624
Feed Name: GBHackers
Okta released security updates for three high-severity vulnerabilities disclosed September 8, 2026: a critical stored XSS (CVE-2026-85982) in the Auth0 AD/LDAP Connector that can be exploited by authenticated users or local actors to run script in admin interfaces; an authorization-bypass (CVE-2026-78626) in Okta Access Gateway affecting Protected Rule checks; and an SQL injection (CVE-2026-78623) in Access Gateway advanced-mode datastores when custom SQL uses unsanitized SAML attributes. Administrators should upgrade the auth0/ad-ldap-connector to 8.0.0+ and Access Gateway to 2026.9.1+, audit Protected Rules and custom SQL datastore queries, and validate SAML attributes where used.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
