Okta
- Total products in the ecosystem
- 16
- Total vulnerabilities (90 days)
- 18
en
Verify to analyze this security profile
As of 09/18/2026, Okta recorded 18 security vulnerabilities in the last 90 days across 5 products, including 4 rated High or above and 0 known exploited vulnerabilities (KEV) that should be prioritized for immediate remediation.
Over the last 90 days, Okta Access Gateway had the most security vulnerabilities in the Okta ecosystem, with 11 vulnerabilities—approximately 61.11% of the provider's total vulnerabilities during this period.
| Vulnerability | Exploitation status | Fix | Affected product | Published | Severity |
|---|---|---|---|---|---|
CVE-2026-78622Improper Link Resolution in Okta Verify for Windows Uninstaller Data Removal | Exploitation statusNot known exploited | FixYes | Affected productOkta Verify for Windows | Published09/08/2026 | SeverityMedium |
CVE-2026-78631Improper Restriction of Sensitive Information in Okta Hyperdrive Agent Logging | Exploitation statusNot known exploited | FixYes | Affected productOkta Hyperdrive Agent | Published09/08/2026 | SeverityMedium |
CVE-2026-78630Improper Input Neutralization in Okta Access Gateway SNMP Configuration Processing | Exploitation statusNot known exploited | FixYes | Affected productOkta Access Gateway | Published09/08/2026 | SeverityMedium |
CVE-2026-78629Improper Authentication Verification in the Okta Hyperdrive Agent MFA Response Handling | Exploitation statusNot known exploited | FixYes | Affected productOkta Hyperdrive Agent | Published09/08/2026 | SeverityMedium |
CVE-2026-78635Improper Input Validation in the Okta Privileged Access SSH Client URL Handler Argument | Exploitation statusNot known exploited | FixYes | Affected productOkta Privileged Access Client | Published09/08/2026 | SeverityMedium |
CVE-2026-78620Improper Path Validation in Okta Access Gateway Kerberos Configuration Handling | Exploitation statusNot known exploited | FixYes | Affected productOkta Access Gateway | Published09/08/2026 | SeverityMedium |
CVE-2026-78579Improper Input Sanitization in Okta Access Gateway LDAP Datastore Filter Interpolation | Exploitation statusNot known exploited | FixYes | Affected productOkta Access Gateway | Published09/08/2026 | SeverityMedium |
CVE-2026-78627Improper Credential Protection in Okta Hyperdrive Integration Installer Logging | Exploitation statusNot known exploited | FixYes | Affected productOkta Hyperdrive Integration Plugin | Published09/08/2026 | SeverityHigh |
CVE-2026-78574Improper Assembly Resolution in Okta Hyperdrive Integration Plugin Registry Handling | Exploitation statusNot known exploited | FixYes | Affected productOkta Hyperdrive Integration Plugin | Published09/08/2026 | SeverityHigh |
CVE-2026-78626Improper Input Sanitization in Okta Access Gateway Protected Rules | Exploitation statusNot known exploited | FixYes | Affected productOkta Access Gateway | Published09/08/2026 | SeverityHigh |
CVE-2026-78625Insufficient Validation of Dashboard Application Labels in Okta Access Gateway Dashboard Site Configuration | Exploitation statusNot known exploited | FixYes | Affected productOkta Access Gateway | Published09/08/2026 | SeverityMedium |
CVE-2026-78624Improper Path Validation in Okta Access Gateway Backup and Restore Functionality | Exploitation statusNot known exploited | FixYes | Affected productOkta Access Gateway | Published09/08/2026 | SeverityMedium |
CVE-2026-78560Improper Authentication Validation in Okta Access Gateway Pass-Through Authentication Source | Exploitation statusNot known exploited | FixYes | Affected productOkta Access Gateway | Published09/08/2026 | SeverityMedium |
CVE-2026-78552Validation Bypass in Okta Access Gateway Custom Directives | Exploitation statusNot known exploited | FixYes | Affected productOkta Access Gateway | Published09/08/2026 | SeverityMedium |
CVE-2026-78623Improper Handling of SAML Assertion Attributes in Okta Access Gateway Advanced Mode Datastores | Exploitation statusNot known exploited | FixYes | Affected productOkta Access Gateway | Published09/08/2026 | SeverityHigh |
CVE-2026-78550Improper Input Handling in Okta Access Gateway Management Console Exception Handler | Exploitation statusNot known exploited | FixYes | Affected productOkta Access Gateway | Published09/08/2026 | SeverityMedium |
CVE-2026-78545Improper Input Sanitization in Okta Access Gateway Application Label Configuration | Exploitation statusNot known exploited | FixYes | Affected productOkta Access Gateway | Published09/08/2026 | SeverityMedium |
CVE-2026-77585Improper Validation of SSH Target in Okta Privileged Access Client | Exploitation statusNot known exploited | FixYes | Affected productOkta Privileged Access Client | Published08/25/2026 | SeverityMedium |
CVE-2025-67505Race condition in the Okta Java SDK | Exploitation statusNot known exploited | FixYes | Affected productokta-sdk-java | Published12/10/2025 | SeverityHigh |
CVE-2025-66033Improper Memory Cleanup in the Okta Java SDK | Exploitation statusNot known exploited | FixYes | Affected productokta-sdk-java | Published12/10/2025 | SeverityMedium |
CVE-2025-7371 | Exploitation statusNot known exploited | FixYes | Affected productOkta On-Premises Provisioning Agent | Published07/22/2025 | SeverityMedium |
CVE-2024-9875 | Exploitation statusNot known exploited | FixYes | Affected productOkta Privileged Access Server Agent (SFTD) | Published11/20/2024 | SeverityHigh |
CVE-2024-9191 | Exploitation statusNot known exploited | FixYes | Affected productOkta Verify for Windows | Published11/01/2024 | SeverityHigh |
CVE-2024-10327 | Exploitation statusNot known exploited | FixYes | Affected productOkta Verify for iOS | Published10/24/2024 | SeverityHigh |
CVE-2024-7061 | Exploitation statusNot known exploited | FixYes | Affected productOkta Verify for Windows | Published08/07/2024 | SeverityMedium |
CVE-2024-0981 | Exploitation statusNot known exploited | FixYes | Affected productOkta Browser Plugin | Published07/23/2024 | SeverityHigh |
CVE-2024-0980 | Exploitation statusNot known exploited | FixYes | Affected productOkta Verify for Windows | Published03/27/2024 | SeverityHigh |
CVE-2023-0392 | Exploitation statusNot known exploited | FixYes | Affected productLDAP Agent | Published11/08/2023 | SeverityLow |
CVE-2021-45094 | Exploitation statusPublic exploit | FixNot confirmed | Affected productNot confirmed | Published07/20/2023 | SeverityUnknown |
CVE-2023-0093 | Exploitation statusNot known exploited | FixNot confirmed | Affected productAdvanced Server Access | Published03/06/2023 | SeverityHigh |
CVE-2022-3145 | Exploitation statusNot known exploited | FixNot confirmed | Affected productOkta OIDC Middleware | Published01/12/2023 | SeverityMedium |
CVE-2022-1697 | Exploitation statusNot confirmed | FixNot confirmed | Affected productOkta Active Directory Agent | Published09/06/2022 | SeverityUnknown |
CVE-2022-1030 | Exploitation statusNot confirmed | FixNot confirmed | Affected productAdvanced Server Access Client | Published03/23/2022 | SeverityUnknown |
CVE-2022-24295 | Exploitation statusNot confirmed | FixNot confirmed | Affected productOkta Advanced Server Access Client | Published02/21/2022 | SeverityUnknown |
CVE-2021-28113 | Exploitation statusNot confirmed | FixNot confirmed | Affected productNot confirmed | Published04/02/2021 | SeverityMedium |
CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.
Explore CyStack VulnScan