CVE-2026-78622

The Okta Verify for Windows uninstaller does not verify whether the user data directory is a filesystem junction before deleting its contents with elevated privileges. The delete operation follows the junction target, resulting in recursive deletion of unintended directory contents.

  • Published Sep 8, 2026
  • CVSS 6.0 medium
  • 0.1% chance of exploitation in the next 30 days (EPSS)

Affected software

CVE-2026-78622 at the National Vulnerability Database