CVE-2026-78622
בינונית 6.0
תיאור (מקור, אנגלית)
The Okta Verify for Windows uninstaller does not verify whether the user data directory is a filesystem junction before deleting its contents with elevated privileges. The delete operation follows the junction target, resulting in recursive deletion of unintended directory contents.
מדדים
- CVSS 3.1
-
6.0 (MEDIUM)
מקור הציון: CNA
CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:H - EPSS — סבירות ניצול
- 0% (אחוזון 000) נכון ל-10/10/2026
- CWE
- CWE-59