Okta Session Fixation Advisory — OKTA-SA-2026-001
Publicly Published
2026-03-01 10:14
Summary
Okta disclosed a session fixation vulnerability in their Classic Engine authentication flow. Organizations using Classic Engine should migrate to Identity Engine.
Impacted Systems
Patient Portal SSO, Telehealth Platform SSO, Staff Scheduling SSO
Mitigation
1. Migrate from Classic Engine to Identity Engine. 2. Enable session binding to IP address. 3. Reduce session timeout to 4 hours.
Need Personalized Impact Analysis?
Sign up for GlassTrace to get personalized impact analysis for your organization.
Sign up for GlassTrace