Improper Link Resolution in Okta Verify for Windows Uninstaller Data Removal CVE-2026-78622 - Sep 8, 2026
Description
The Okta Verify for Windows uninstaller does not verify whether the user data directory is a filesystem junction before deleting its contents with elevated privileges. The delete operation follows the junction target, resulting in recursive deletion of unintended directory contents.
Affected product and versions
Customers using the Okta Verify for Windows client versions 5.1.3 through 6.12.3 are affected.
Preconditions
This applies if the following preconditions are present:
Okta Verify for Windows (versions 5.1.3 through 6.12.3) is installed on the host system.
A local user has low-privileged interactive access to create filesystem junctions on the host.
An administrative user or system process subsequently initiates the uninstallation.
Customer Recommendations
To remediate this vulnerability, upgrade the Okta Verify for Windows client to version 7.0.0 or greater.
Download version 7.0.1 of Okta Verify for Windows
Resolution
The vulnerability is present in Okta Verify for Windows versions 5.1.3 to 6.12.3 and is resolved in Okta Verify for Windows version 7.0.0.
CVE details
CVE ID | |
Published Date | 2026-09-08 |
Vulnerability Type | Improper Link Resolution |
CWE | CWE-59 – Improper Link Resolution Before File Access |
CVSS v3 | Score: 6.0 Vector string: CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:H |