Description
The Okta Verify for Windows uninstaller does not verify whether the user data directory is a filesystem junction before deleting its contents with elevated privileges. The delete operation follows the junction target, resulting in recursive deletion of unintended directory contents.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
Vendor Solution
Upgrade the Okta Verify for Windows client to version 7.0.0 or greater.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Tue, 08 Sep 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Okta Verify for Windows uninstaller does not verify whether the user data directory is a filesystem junction before deleting its contents with elevated privileges. The delete operation follows the junction target, resulting in recursive deletion of unintended directory contents. | |
| Title | Improper Link Resolution in Okta Verify for Windows Uninstaller Data Removal | |
| Weaknesses | CWE-59 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: Okta
Published:
Updated: 2026-09-08T20:16:15.208Z
Reserved: 2026-08-24T21:54:34.029Z
Link: CVE-2026-78622
No data.
No data.
No data.
OpenCVE Enrichment
No data.
Weaknesses