Okta maintains a focused portfolio of identity and access management products, including advanced server access, API management, and directory-integration components that sit in authentication and authorization flows across enterprise infrastructure. The recurring vulnerability signal centers on path-handling, code-injection, and process-synchronization weaknesses characteristic of systems that parse user input and execute external commands during authentication and policy enforcement. Defenders should prioritize patches in directory agents and access gateways that sit on the network perimeter; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Okta over time
Of all the CVEs published by Okta as a CNA, 61.5% affect products that Okta develops as a vendor.
Of all the CVEs published that affect products developed by Okta, 66.7% are self-published by Okta as a CNA.
Signals from CVEs in this vendor scope (12 CVEs).
12 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-24295HIGH Okta Advanced Server Access Client for Windows prior to version 1.57.0 was found to be vulnerable to command injection via a specially crafted URL. | Feb 21, 2022 | 8.8 | 37 | NO | NO |
CVE-2021-28113MEDIUM A command injection vulnerability in the cookieDomain and relayDomain parameters of Okta Access Gateway before 2020.9.3 allows attackers (with admin access to the Okta Access Gatew | Apr 2, 2021 | 6.7 | 32 | NO | NO |
CVE-2025-67505HIGH Okta Java Management SDK facilitates interactions with the Okta management API. In versions 11.0.0 through 20.0.0, race conditions may arise from concurrent requests using the ApiC | Dec 10, 2025 | 8.4 | 27 | NO | NO |
CVE-2024-9191HIGH The Okta Device Access features, provided by the Okta Verify agent for Windows, provides access to the OktaDeviceAccessPipe, which enables attackers in a compromised device to retr | Nov 1, 2024 | 7.8 | 24 | NO | NO |
CVE-2024-7061HIGH Okta Verify for Windows is vulnerable to privilege escalation through DLL hijacking. The vulnerability is fixed in Okta Verify for Windows version 5.0.2. To remediate this vulnerab | Aug 7, 2024 | 7.8 | 22 | NO | NO |
CVE-2023-0093HIGH Okta Advanced Server Access Client versions 1.13.1 through 1.65.0 are vulnerable to command injection due to the third party library webbrowser. An outdated library, webbrowser, us | Mar 6, 2023 | 8.8 | 22 | NO | NO |
CVE-2022-1030HIGH Okta Advanced Server Access Client for Linux and macOS prior to version 1.58.0 was found to be vulnerable to command injection via a specially crafted URL. An attacker, who has kno | Mar 23, 2022 | 8.8 | 22 | NO | NO |
CVE-2023-0392MEDIUM The LDAP Agent Update service with versions prior to 5.18 used an unquoted path, which could allow arbitrary code execution. | Nov 8, 2023 | 6.7 | 19 | NO | NO |
CVE-2022-3145MEDIUM An open redirect vulnerability exists in Okta OIDC Middleware prior to version 5.0.0 allowing an attacker to redirect a user to an arbitrary URL. | Jan 12, 2023 | 4.7 | 19 | NO | NO |
CVE-2025-66033MEDIUM Okta Java Management SDK facilitates interactions with the Okta management API. In versions 21.0.0 through 24.0.0, specific multithreaded implementations may encounter memory issue | Dec 10, 2025 | 5.3 | 18 | NO | NO |
Signals from CVEs in this vendor scope (12 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Okta.
Media articles that mention a CVE ID that affects a product developed by Okta — matched by CVE ID, not by vendor name.