The full story
Improper Link Resolution in Okta Verify for Windows Uninstaller Data Removal CVE-2026-78622 - Sep 8, 2026. A security weakness in Windows is being tracked as CVE-2026-78622. The Okta Verify for Windows uninstaller does not verify whether the user data directory is a filesystem junction before deleting its contents with elevated privileges.
To remediate this vulnerability, upgrade the Okta Verify for Windows client to version 7 0 0 or greater.
What the reporting is based on
Improper Link Resolution in Okta Verify for Windows Uninstaller Data Removal CVE-2026-78622 - Sep 8, 2026
The Okta Verify for Windows uninstaller does not verify whether the user data directory is a filesystem junction before deleting its contents with elevated privileges. To remediate this vulnerability, upgrade the Okta Verify for Windows client to version 7 0 0 or greater.
Open sourceReporting ends here. The sections below are CyberDeltaForce analysis and defender-focused interpretation.
What this means
Risk depends on whether Okta and the affected component are deployed and reachable, because the reported flaw can lead to privilege escalation. Exposure, privilege, business criticality and compensating controls should determine remediation priority.
What security teams should check now
- Inventory Okta deployments and confirm whether the affected component and vulnerable release are present.
- Apply the vendor patch or mitigation for CVE-2026-78622 and validate the affected path after remediation.
What is not yet confirmed
- Available reporting does not currently indicate exploitation, but that can change as vendor, government or threat-intelligence reporting develops.