HomepageOkta logo

Improper Link Resolution in Okta Verify for Windows Uninstaller Data Removal CVE-2026-78622 - Sep 8, 2026

View all security advisories

Description

The Okta Verify for Windows uninstaller does not verify whether the user data directory is a filesystem junction before deleting its contents with elevated privileges. The delete operation follows the junction target, resulting in recursive deletion of unintended directory contents.

Affected product and versions

Customers using the Okta Verify for Windows client versions 5.1.3 through 6.12.3 are affected.

Preconditions

This applies if the following preconditions are present:

  1. Okta Verify for Windows (versions 5.1.3 through 6.12.3) is installed on the host system.

  2. A local user has low-privileged interactive access to create filesystem junctions on the host.

  3. An administrative user or system process subsequently initiates the uninstallation.

Customer Recommendations

To remediate this vulnerability, upgrade the Okta Verify for Windows client to version 7.0.0 or greater.

Download version 7.0.1 of Okta Verify for Windows

Resolution

The vulnerability is present in Okta Verify for Windows versions 5.1.3 to 6.12.3 and is resolved in Okta Verify for Windows version 7.0.0.

CVE details

CVE ID

CVE-2026-78622

Published Date

2026-09-08

Vulnerability Type

Improper Link Resolution

CWE

CWE-59 – Improper Link Resolution Before File Access

CVSS v3

Score: 6.0

Vector string: CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:H