CVE-2026-78622: Improper Link Resolution in Okta Verify for Windows Uninstaller Data Removal

Published Sep 8, 2026
·
Updated

The Okta Verify for Windows uninstaller does not verify whether the user data directory is a filesystem junction before deleting its contents with elevated privileges. The delete operation follows the junction target, resulting in recursive deletion of unintended directory contents.

Affected Software

1 affected component
Okta Okta Verify for Windows

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Okta Verify for Windows client to a version that resolves this vulnerability.

    Fixed in 7.0.0

Event History

Sep 8, 2026
CVE Published
via MITRE·08:16 PM
Data Sourced
via MITRE·08:16 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·09:18 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

What access and interaction are required to exploit this issue?

An attacker needs local access with low privileges and must be able to induce a user to run the Okta Verify for Windows uninstaller. Exploitation also requires creating or controlling a filesystem junction for the uninstaller's user data directory.

2

What is the likely impact if exploitation succeeds?

The elevated uninstaller can recursively delete the contents of the directory targeted by the junction. The stated impact is integrity and availability loss; no confidentiality impact is identified.

3

How can an organization tell whether it may be affected?

Systems with Okta Verify for Windows are the relevant population. A system is at risk during uninstallation if its Okta Verify user data directory has been replaced or redirected with a filesystem junction.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203