Okta published security advisories resolving six vulnerabilities across several enterprise identity products on September 9, 2026. These critical Okta vulnerabilities impact the Auth0 AD/LDAP Connector, Okta Access Gateway, and the Okta Hyperdrive Integration plugin. Therefore, security teams must update these components immediately to prevent privilege escalation and unauthorized access.
- Total: 6 CVEs
- Severity: 1 Critical · 5 High
- Actively exploited: None confirmed
- Highest severity: 9.0 (Critical · CVSSv3) — CVE-2026-85982
- Action: Apply the latest security updates now
Notable CVEs
| CVE | CVSS (CVSSv3) | Type | Fixed in | Status |
|---|---|---|---|---|
| CVE-2026-85982 | 9 | CWE-79 | — | Not exploited |
| CVE-2026-78626 | 8.1 | CWE-863 | 2026.9.1 | Not exploited |
| CVE-2026-85983 | 7.8 | CWE-94 | — | Not exploited |
| CVE-2026-78623 | 7.7 | CWE-89 | 2026.9.1 | Not exploited |
| CVE-2026-78574 | 7.5 | CWE-426 | 1.5.2 | Not exploited |
| CVE-2026-78627 | 7.3 | CWE-532 | 1.5.2 | Not exploited |
Why This Threat Matters
Industry estimates indicate that Okta secures more than 18,000 organizations worldwide. Identity gateways protect mission-critical infrastructure and sensitive enterprise directories. Consequently, unpatched Okta vulnerabilities expose internal networks to administrative takeover and corporate data theft. In addition, attackers can bypass authentication controls and compromise user directories directly.
How the Attack Works
The most severe flaw, CVE-2026-85982, affects the Auth0 connector. The vendor advisory notes, “The Auth0 AD/LDAP Connector is vulnerable to stored Cross-Site Scripting (XSS) issues due to improper HTML encoding of data in search results and updater log content displayed in the admin panel.” Consequently, malicious actors with basic directory access inject scripts that execute in administrator browsers.
Furthermore, CVE-2026-78626 introduces serious authorization weaknesses in Okta Access Gateway. As Okta reported, “The Okta Access Gateway improperly handles input sanitization and regular expression evaluation within its Protected Rule authorization check, resulting in an authorization bypass.” In addition, CVE-2026-78623 allows attackers to execute unintended SQL commands by injecting unsanitized SAML assertion attributes. Meanwhile, the Hyperdrive plugin allows local users to execute unverified assemblies or read plaintext client secrets from installation logs.
Affected Versions
Auth0 connector versions prior to 8.0.0 contain the stored scripting and privilege escalation flaws. Similarly, Okta Access Gateway builds prior to version 2026.9.1 remain vulnerable to authorization bypass and SQL injection. Additionally, the Hyperdrive Integration plugin versions 1.2.0 through 1.5.1 carry assembly loading and logging flaws. Fortunately, Okta confirmed that no active in-the-wild exploitation or public proof-of-concept exploits exist for these issues.
Patch and Mitigation Steps
Administrators must install security updates across all affected environments without delay. Specifically, teams should upgrade the Auth0 connector to version 8.0.0 or greater. Next, administrators should update Okta Access Gateway to version 2026.9.1. Furthermore, organizations deploying the Hyperdrive plugin must install version 1.5.2 immediately. Finally, security teams can review full guidance in the official Okta security advisories portal.
Support Our Threat Intelligence
Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!