OktaCVE-2026-78622
Okta Verify for Windows: link following
Medium6.0CVE-2026-78622 · Published Sep 8, 2026 · updated Sep 10, 2026
The Okta Verify for Windows uninstaller does not verify whether the user data directory is a filesystem junction before deleting its contents with elevated privileges. The delete operation follows the junction target, resulting in recursive deletion of unintended directory contents.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Okta Verify for Windows Product | >= 5.1.3, < 7.0.0 | 7.0.0 |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:H
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-59
More Okta advisories
All Okta| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 8 | Okta Auth0 AD/LDAP Connector: missing authentication | Medium6.7 | No fix yet |
| Sep 8 | Okta Auth0 AD/LDAP Connector: cross-site scripting | Critical9.0 | No fix yet |
| Sep 8 | Okta Auth0 AD/LDAP Connector: code execution | High7.8 | No fix yet |
| Sep 8 | The react-native-auth0 SDK's web platform implementation does not scope its... | Medium6.5 | 5.11.1 |
| Sep 8 | The Okta Hyperdrive agent plugin returns a success response without a signed... | Medium5.6 | 1.5.2 |
| Sep 8 | Okta Access Gateway: command injection | Medium6.7 | 2026.9.1 |