Improper Link Resolution Vulnerability in Okta Verify for Windows by Okta
CVE-2026-78622

6MEDIUM

Key Information:

Vendor

Okta

Vendor
CVE Published:
8 September 2026

What is CVE-2026-78622?

The Okta Verify for Windows software exhibits a security issue during its uninstallation process. Specifically, when a user attempts to uninstall the application, the uninstaller fails to properly verify if the user data directory is a filesystem junction. This oversight allows the uninstaller to navigate to the target of the junction, leading to the potential for unintended recursive deletion of directory contents. This means that crucial user data located in linked directories can be permanently erased without any prompt for confirmation, posing a significant risk to data integrity and users' operational environment.

Affected Version(s)

Okta Verify for Windows 5.1.3 < 7.0.0

References

CVSS V3.1

Score:
6
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.