CVE-2026-78622: Improper Link Resolution in Okta Verify for Windows Uninstaller Data Removal
The Okta Verify for Windows uninstaller does not verify whether the user data directory is a filesystem junction before deleting its contents with elevated privileges. The delete operation follows the junction target, resulting in recursive deletion of unintended directory contents.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Okta Verify for Windows clientto a version that resolves this vulnerability.Fixed in 7.0.0
Event History
Frequently Asked Questions
What access and interaction are required to exploit this issue?
An attacker needs local access with low privileges and must be able to induce a user to run the Okta Verify for Windows uninstaller. Exploitation also requires creating or controlling a filesystem junction for the uninstaller's user data directory.
What is the likely impact if exploitation succeeds?
The elevated uninstaller can recursively delete the contents of the directory targeted by the junction. The stated impact is integrity and availability loss; no confidentiality impact is identified.
How can an organization tell whether it may be affected?
Systems with Okta Verify for Windows are the relevant population. A system is at risk during uninstallation if its Okta Verify user data directory has been replaced or redirected with a filesystem junction.