The Okta Access Gateway does not sanitize SAML assertion attribute values before interpolating them into LDAP search filters in the LDAP datastore configuration. The raw values are substituted directly into the filter string and passed to the LDAP search operation, resulting in modification of the intended query logic.
Metrics
Affected Vendors & Products
References
History
Thu, 10 Sep 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 08 Sep 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Okta Access Gateway does not sanitize SAML assertion attribute values before interpolating them into LDAP search filters in the LDAP datastore configuration. The raw values are substituted directly into the filter string and passed to the LDAP search operation, resulting in modification of the intended query logic. | |
| Title | Improper Input Sanitization in Okta Access Gateway LDAP Datastore Filter Interpolation | |
| Weaknesses | CWE-90 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Okta
Published: 2026-09-08T20:12:53.558Z
Updated: 2026-09-10T14:37:56.057Z
Reserved: 2026-08-24T20:50:31.443Z
Link: CVE-2026-78579
Updated: 2026-09-10T14:37:50.856Z
Status : Undergoing Analysis
Published: 2026-09-08T20:18:36.590
Modified: 2026-09-10T15:17:41.460
Link: CVE-2026-78579
No data.