Description
The Okta Verify for Windows uninstaller does not verify whether the user data directory is a filesystem junction before deleting its contents with elevated privileges. The delete operation follows the junction target, resulting in recursive deletion of unintended directory contents.
Published: 2026-09-08
Score: 6 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Data Loss
Action: Patch
AI Analysis

Impact

The vulnerability arises when the Okta Verify for Windows uninstaller does not validate that the user data directory is a filesystem junction before deleting its contents. Because the delete operation follows the junction target, it can recursively remove content in directories that are not intended to be deleted. This results in unintended data loss or removal of user data from locations outside the application data area, presenting a moderate security consequence as it can affect confidentiality and availability for user files. The weakness is identified as improper handling of resource references (CWE-59).

Affected Systems

Okta Verify for Windows, all installations that use the uninstaller component where the user data directory might be a junction. Users of Okta Verify 7.0.0 and newer are not impacted as the issue has been fixed in those releases.

Risk and Exploitability

The vulnerability is assessed with a CVSS score of 6, indicating medium severity. EPSS data is not available, so the current probability of exploitation is unknown, though the lack of a public exploit and the unpatched risk suggest a relatively low likelihood until an exploit emerges. The vulnerability is not listed in the CISA KEV catalog. Exploitation would likely require a user or attacker with the ability to initiate the uninstall process with elevated privileges on the target Windows machine, which could be achieved locally or remotely if privilege escalation is possible. Once triggered, the uninstaller would delete files under any junctioned directories, leading to loss of data that may be critical for the user or organization.

Generated by OpenCVE AI on September 9, 2026 at 09:23 UTC.

Remediation

Vendor Solution

Upgrade the Okta Verify for Windows client to version 7.0.0 or greater.


OpenCVE Recommended Actions

  • Apply the vendor patch by upgrading Okta Verify for Windows to version 7.0.0 or higher.
  • If upgrading is not immediately possible, restrict the uninstaller from running with elevated privileges by removing or disabling the ‘Run as administrator’ requirement or preventing its execution entirely until patched.
  • Review the file junction configuration on systems running the vulnerable uninstaller and protect directories that contain important data by limiting junction points or applying access controls.

Generated by OpenCVE AI on September 9, 2026 at 09:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 13 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Okta
Okta okta Verify For Windows
Vendors & Products Okta
Okta okta Verify For Windows

Thu, 10 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Description The Okta Verify for Windows uninstaller does not verify whether the user data directory is a filesystem junction before deleting its contents with elevated privileges. The delete operation follows the junction target, resulting in recursive deletion of unintended directory contents.
Title Improper Link Resolution in Okta Verify for Windows Uninstaller Data Removal
Weaknesses CWE-59
References
Metrics cvssV3_1

{'score': 6, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:H'}


Subscriptions

Okta Okta Verify For Windows
cve-icon MITRE

Status: PUBLISHED

Assigner: Okta

Published:

Updated: 2026-09-10T14:42:00.497Z

Reserved: 2026-08-24T21:54:34.029Z

Link: CVE-2026-78622

cve-icon Vulnrichment

Updated: 2026-09-10T14:41:55.124Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-08T21:18:41.233

Modified: 2026-09-10T15:17:41.753

Link: CVE-2026-78622

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-13T20:06:44Z

Weaknesses
  • CWE-59

    Improper Link Resolution Before File Access ('Link Following')