










The Okta Access Gateway improperly handles input sanitization and regular expression evaluation within its Protected Rule authorization check, resulting in an authorization bypass when an administrator has explicitly configured a Protected Rule policy on one or more application resources.
Customers using the Okta Access Gateway versions prior to 2026.9.1 are affected.
This applies if the following preconditions are present:
A Protected Rule policy is actively configured on one or more application resources.
An authenticated user holds a valid account assigned to the application at any privilege level.
To remediate this vulnerability, upgrade Okta Access Gateway to version 2026.9.1 or greater.
The vulnerability is present in Okta Access Gateway versions prior to 2026.9.1 and is resolved in version 2026.9.1.
此内容由惯性聚合(RSS阅读器)自动聚合整理,仅供阅读参考。 原文来自 — 版权归原作者所有。