SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-78622

MEDIUM · CVSS 6 EPSS 0.10%

Source: NVD + CISA KEV + EPSS · Published 2026-09-08 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The vulnerability in Okta Verify for Windows allows the uninstaller to delete unintended directory contents due to a failure in verifying whether the user data directory is a filesystem junction, leading to potential data loss. This issue poses a risk to users who may inadvertently lose critical data if the uninstaller is executed without proper safeguards. Organizations using Okta Verify on Windows should prioritize addressing this vulnerability to prevent accidental data deletion.

CVE
CVE-2026-78622
Severity
MEDIUM
CVSS
6
EPSS
0.10%
Windows

Original NVD Description

The Okta Verify for Windows uninstaller does not verify whether the user data directory is a filesystem junction before deleting its contents with elevated privileges. The delete operation follows the junction target, resulting in recursive deletion of unintended directory contents.