CVE-2026-78624EPSS p37.5%

CVE-2026-78624CVE-2026-78624

okta / access_gateway

Description

The Okta Access Gateway backup restore function does not validate the filename embedded in an encrypted backup payload. This results in writing file contents to unintended locations on the appliance filesystem.

Scoring

CVSS 4.9 ()
VectorCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
EPSS0.46% probability of exploitation · percentile 37.5% · 2026-10-05T12:00:23Z
Last modified2026-09-22
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.