PT-2026-88433 · Okta · Okta Verify For Windows

CVE-2026-78622

·

Published

2026-09-08

·

Updated

2026-09-08

CVSS v3.1

6.0

Medium

VectorAV:L/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:H
The Okta Verify for Windows uninstaller does not verify whether the user data directory is a filesystem junction before deleting its contents with elevated privileges. The delete operation follows the junction target, resulting in recursive deletion of unintended directory contents.

Fix

Link Following

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-78622

Affected Products

Okta Verify For Windows