{"id":"CVE-2026-78622","title":"The Okta Verify for Windows uninstaller does not verify whether the user data directory is a filesystem junction before deleting its contents with elevated privileges","summary":"The Okta Verify for Windows uninstaller does not verify whether the user data directory is a filesystem junction before deleting its contents with elevated privileges. The delete operation follows the junction target, resulting in recurs…","severity":"medium","cvss":6,"cvssVector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:H","cwe":["CWE-59"],"vendor":"Okta","product":"Okta Verify for Windows","affected":["verify_for_windows >= 5.1.3 < 7.0.0"],"published":"2026-09-08","updated":"2026-09-10","sourceUpdated":"2026-09-10T15:17:41.753","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-78622","references":[{"url":"https://trust.okta.com/security-advisories/improper-link-resolution-in-okta-verify-for-windows-uninstaller-data-removal-cve-2026-78622","label":"psirt@okta.com"}],"tags":["nvd","cve.org"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-09-10T14:41:50.671834Z"},"epss":0.00099,"epssPercentile":0.00903,"ingestedAt":"2026-09-08T21:11:12.373Z","slug":"CVE-2026-78622","body":"## Overview\n\nThe Okta Verify for Windows uninstaller does not verify whether the user data directory is a filesystem junction before deleting its contents with elevated privileges. The delete operation follows the junction target, resulting in recursive deletion of unintended directory contents.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":33,"depthScoreParts":{"impact":33,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}