CVE-2026-78622
6
CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:H
Summary
The Okta Verify for Windows uninstaller does not verify whether the user data directory is a filesystem junction before deleting its contents with elevated privileges. The delete operation follows the junction target, resulting in recursive deletion of unintended directory contents.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Okta | Okta Verify for Windows | 5.1.3 < 7.0.0 | affected |
Weaknesses
- CWE-59: Improper Link Resolution Before File Access
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.