PT-2026-84403 · Konga · Konga

·

CVE-2026-45221

·

Published

2026-09-01

·

Updated

2026-09-02

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Konga versions prior to 2.1.0
Description A privilege escalation issue allows low-privileged local attackers to execute arbitrary code. This is achieved by placing attacker-controlled OpenSSL configuration or library files in a hardcoded filesystem path that is not present in default installations. On Windows systems, the missing directory is located in a path writable by any authenticated local user, allowing them to create the directory and insert malicious files. These files then execute with the privileges of the user or service account that starts Konga.
Recommendations Update to version 2.1.0 or later.

Fix

LPE

Uncontrolled Search Path Element

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-45221

Affected Products

Konga