PT-2026-102672 · Akaunting · Akaunting

·

CVE-2022-51019

·

Published

2026-09-29

·

Updated

2026-09-29

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Akaunting versions prior to 2.1.31
Description An OS command injection issue exists in the module installation and update flow. Authenticated users with admin panel access can execute arbitrary commands on the server by injecting shell metacharacters into the alias parameter, which is passed unvalidated to shell command execution.
Recommendations Update to version 2.1.31 or later. Avoid using the alias parameter during module installation or updates until the system is updated.

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-51019

Affected Products

Akaunting