vendor

okta

17 thingsrelated by NVD

Its products

access gateway 11 hyperdrive 4 java management sdk 2

Being told

Watch: its feed Ask more of it

The feed says each thing that enters, leaves or changes; a reader adds its address, /zetlyn/trackers/cve/things.atom?q=…, to theirs.

Every thing

The Okta Hyperdrive Agent writes the decoded SAML bearer assertion to a local application log file at the default log level on every…
CVE-2026-78631
Severity medium
The Okta Access Gateway does not neutralize shell metacharacters in SNMP configuration values before a privileged script uses them to…
CVE-2026-78630
Severity medium
The Okta Hyperdrive agent plugin returns a success response without a signed SAML assertion when the organization's policy requires no MFA…
CVE-2026-78629
Severity medium
The Okta Hyperdrive Integration installer does not mask the OAuth client secret when passed as an MSI property. The credential is recorded…
CVE-2026-78627
Severity medium
The Okta Access Gateway improperly handles input sanitization and regular expression evaluation within its Protected Rule authorization…
CVE-2026-78626
Severity medium
The Okta Access Gateway does not sanitize dashboard label values before writing them into generated PHP configuration files. The generated…
CVE-2026-78625
Severity medium
The Okta Access Gateway backup restore function does not validate the filename embedded in an encrypted backup payload. This results in…
CVE-2026-78624
Severity medium
The Okta Access Gateway does not sanitize SAML assertion values before interpolating them into database queries in the advanced mode…
CVE-2026-78623
Severity critical
The Okta Access Gateway Kerberos configuration handler does not validate file paths specified in event payloads before writing file…
CVE-2026-78620
Severity medium
The Okta Access Gateway does not sanitize SAML assertion attribute values before interpolating them into LDAP search filters in the LDAP…
CVE-2026-78579
Severity medium
The Okta Hyperdrive Integration plugin resolves a required assembly using a registry path within the current user's hive without integrity…
CVE-2026-78574
Severity medium
The Okta Access Gateway includes an optional pass-through authentication source that accepts user identity from a client-supplied HTTP…
CVE-2026-78560
Severity medium
The Okta Access Gateway does not apply its Lua directive restriction to the application-level custom configuration field. The field is…
CVE-2026-78552
Severity medium
The Okta Access Gateway management console passes user-supplied input to eval() without sanitization during an authenticated administrator…
CVE-2026-78550
Severity high
The Okta Access Gateway does not sanitize the application label field before including it in the generated nginx configuration file. The…
CVE-2026-78545
Severity high
Okta Java Management SDK facilitates interactions with the Okta management API. In versions 11.0.0 through 20.0.0, race conditions may…
CVE-2025-67505
Severity high
Okta Java Management SDK facilitates interactions with the Okta management API. In versions 21.0.0 through 24.0.0, specific multithreaded…
CVE-2025-66033
Severity medium