OKTA has released security advisories addressing six vulnerabilities across its Auth0 AD/LDAP Connector, Okta Access Gateway, and the Hyperdrive Integration plugin. The issues, rated as 1 Critical and 5 High, were patched on 9 September 2026, with mitigations advised across all affected environments. The defending guidance emphasises applying the latest updates promptly to prevent privilege escalation and unauthorised access.
The most severe flaw, CVE-2026-85982 (CVSSv3 9.0), affects the Auth0 AD/LDAP Connector and is due to stored Cross‑Site Scripting from improper HTML encoding of data shown in admin panels, enabling script injection in administrator browsers. CVE-2026-78626 (CVSSv3 8.1) concerns Okta Access Gateway, where input sanitisation and regex evaluation weaknesses can lead to an authorization bypass. CVE-2026-78623 (CVSSv3 7.7) enables SQL command execution via unsanitised SAML assertion attributes.
The Hyperdrive Integration plugin presents further risks with assembly loading and access to plaintext client secrets in installation logs, via CVE-2026-78574 (CVSSv3 7.5) and CVE-2026-78627 (CVSSv3 7.3). Across these flaws, Okta reports no active exploitation or public PoCs at the time of disclosure.
Affected versions are Auth0 connector prior to 8.0.0, Okta Access Gateway prior to 2026.9.1, and Hyperdrive plugin versions 1.2.0–1.5.1. Patches mandate upgrading Auth0 to 8.0.0+, Okta Access Gateway to 2026.9.1, and Hyperdrive to 1.5.2. Security teams should follow Okta’s official advisories portal for full guidance.