CVE-2026-78622

The Okta Verify for Windows uninstaller does not verify whether the user data directory is a filesystem junction before deleting its contents with elevated privileges. The delete operation follows the junction target, resulting in recursive deletion of unintended directory contents.
Configurations

No configuration.

History

No history.

Information

Published : 2026-09-08 21:18

Updated : 2026-09-10 15:17


NVD link : CVE-2026-78622

Mitre link : CVE-2026-78622

CVE.ORG link : CVE-2026-78622


JSON object : View

Products Affected

No product.

CWE
CWE-59

Improper Link Resolution Before File Access ('Link Following')