PT-2026-84403 · Konga · Konga
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Konga versions prior to 2.1.0
Description
A privilege escalation issue allows low-privileged local attackers to execute arbitrary code. This is achieved by placing attacker-controlled OpenSSL configuration or library files in a hardcoded filesystem path that is not present in default installations. On Windows systems, the missing directory is located in a path writable by any authenticated local user, allowing them to create the directory and insert malicious files. These files then execute with the privileges of the user or service account that starts Konga.
Recommendations
Update to version 2.1.0 or later.
Fix
LPE
Uncontrolled Search Path Element
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Konga