[Git][security-tracker-team/security-tracker][master] auto-nfu: Add rule for Okta
Moritz Muehlenhoff (@jmm)
jmm at debian.org
Wed Sep 9 12:39:46 BST 2026
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker
Commits:
0aa8a8cd by Moritz Muehlenhoff at 2026-09-09T13:39:35+02:00
auto-nfu: Add rule for Okta
Total CVEs from Okta: 35
Total CVEs from Okta with packages assigned: 0
Scope: Okta issues only
- - - - -
2 changed files:
- data/CVE/list
- data/packages/nfu.yaml
Changes:
=====================================
data/CVE/list
=====================================
@@ -608,11 +608,11 @@ CVE-2026-86076 (n8n is an open source workflow automation platform. Prior to 1.1
CVE-2026-86075 (n8n is an open source workflow automation platform. Prior to 2.37.7 an ...)
NOT-FOR-US: n8n
CVE-2026-85983 (The Auth0 AD/LDAP Connector improperly processes a configuration value ...)
- TODO: check
+ NOT-FOR-US: Okta
CVE-2026-85982 (The Auth0 AD/LDAP Connector is vulnerable to stored Cross-Site Scripti ...)
- TODO: check
+ NOT-FOR-US: Okta
CVE-2026-85981 (The administrative panel of the Auth0 AD/LDAP Connector (versions 6.5. ...)
- TODO: check
+ NOT-FOR-US: Okta
CVE-2026-85418 (The Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, ...)
NOT-FOR-US: WordPress plugin
CVE-2026-85133 (The WPLP Cookie Consent WordPress plugin before 4.4.2 does not perfor ...)
@@ -630,7 +630,7 @@ CVE-2026-84908 (The WPFunnels plugin for WordPress is vulnerable to Missing Auth
CVE-2026-84869 (A condition in the ScreenConnect client may allow files to be transfer ...)
TODO: check
CVE-2026-84685 (The react-native-auth0 SDK's web platform implementation does not scop ...)
- TODO: check
+ NOT-FOR-US: Okta
CVE-2026-84293 (The Repeater Fields for Gravity Forms plugin for WordPress is vulnerab ...)
NOT-FOR-US: WordPress plugin
CVE-2026-84222 (The Kirki WordPress plugin before 6.3.0 does not check whether the re ...)
@@ -766,39 +766,39 @@ CVE-2026-78741 (Silverpeas Core <=6.4.6 is vulnerable to Cross Site Scripting (X
CVE-2026-78738 (Silverpeas Core 6.4.6 is vulnerable to Cross Site Scripting (XSS) via ...)
TODO: check
CVE-2026-78635 (The Okta Privileged Access client URL handler does not insert an optio ...)
- TODO: check
+ NOT-FOR-US: Okta
CVE-2026-78631 (The Okta Hyperdrive Agent writes the decoded SAML bearer assertion to ...)
- TODO: check
+ NOT-FOR-US: Okta
CVE-2026-78630 (The Okta Access Gateway does not neutralize shell metacharacters in SN ...)
- TODO: check
+ NOT-FOR-US: Okta
CVE-2026-78629 (The Okta Hyperdrive agent plugin returns a success response without a ...)
- TODO: check
+ NOT-FOR-US: Okta
CVE-2026-78627 (The Okta Hyperdrive Integration installer does not mask the OAuth clie ...)
- TODO: check
+ NOT-FOR-US: Okta
CVE-2026-78626 (The Okta Access Gateway improperly handles input sanitization and regu ...)
- TODO: check
+ NOT-FOR-US: Okta
CVE-2026-78625 (The Okta Access Gateway does not sanitize dashboard label values befor ...)
- TODO: check
+ NOT-FOR-US: Okta
CVE-2026-78624 (The Okta Access Gateway backup restore function does not validate the ...)
- TODO: check
+ NOT-FOR-US: Okta
CVE-2026-78623 (The Okta Access Gateway does not sanitize SAML assertion values before ...)
- TODO: check
+ NOT-FOR-US: Okta
CVE-2026-78622 (The Okta Verify for Windows uninstaller does not verify whether the us ...)
- TODO: check
+ NOT-FOR-US: Okta
CVE-2026-78620 (The Okta Access Gateway Kerberos configuration handler does not valida ...)
- TODO: check
+ NOT-FOR-US: Okta
CVE-2026-78579 (The Okta Access Gateway does not sanitize SAML assertion attribute val ...)
- TODO: check
+ NOT-FOR-US: Okta
CVE-2026-78574 (The Okta Hyperdrive Integration plugin resolves a required assembly us ...)
- TODO: check
+ NOT-FOR-US: Okta
CVE-2026-78560 (The Okta Access Gateway includes an optional pass-through authenticati ...)
- TODO: check
+ NOT-FOR-US: Okta
CVE-2026-78552 (The Okta Access Gateway does not apply its Lua directive restriction t ...)
- TODO: check
+ NOT-FOR-US: Okta
CVE-2026-78550 (The Okta Access Gateway management console passes user-supplied input ...)
- TODO: check
+ NOT-FOR-US: Okta
CVE-2026-78545 (The Okta Access Gateway does not sanitize the application label field ...)
- TODO: check
+ NOT-FOR-US: Okta
CVE-2026-77827 (Maono Link 3.8.13 MaonoAiServices Windows service allows local privile ...)
TODO: check
CVE-2026-77187 (The My Calendar \u2013 Accessible Event Manager plugin for WordPress i ...)
=====================================
data/packages/nfu.yaml
=====================================
@@ -217,6 +217,8 @@
cna: ProgressSoftware
- reason: Proofpoint
cna: Proofpoint
+- reason: Okta
+ cna: Okta
- reason: OpenAI
cna: OAI
- reason: OMRON
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/0aa8a8cdb010bf2fbbd61e5a01125635985e6721
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/0aa8a8cdb010bf2fbbd61e5a01125635985e6721
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260909/4b251969/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list