CVE-2026-45221
Last modified
CVE-2026-45221 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. Konga before 2.1.0 contains a privilege escalation vulnerability that allows low-privileged local attackers to execute arbitrary code by planting attacker-controlled OpenSSL configuration or library files in a hardcoded filesystem path absent from default installations. On Windows, the missing directory resides in a location writable by any authenticated local user, enabling attackers to create the directory and place malicious files that execute at the privilege level of the user or service account that launches Konga, facilitating privilege escalation.. EPSS estimates a 0.13% chance of exploitation in the next 30 days.
Description
Konga before 2.1.0 contains a privilege escalation vulnerability that allows low-privileged local attackers to execute arbitrary code by planting attacker-controlled OpenSSL configuration or library files in a hardcoded filesystem path absent from default installations. On Windows, the missing directory resides in a location writable by any authenticated local user, enabling attackers to create the directory and place malicious files that execute at the privilege level of the user or service account that launches Konga, facilitating privilege escalation.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| EASYBYTE Software | Konga | < 2.1.0 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-45221?
How severe is CVE-2026-45221?
How do I fix CVE-2026-45221?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-45216Incorrect Privilege Assignment vulnerability in StoreApps Sm…8.8
- CVE-2026-45217Authentication Bypass Using an Alternate Path or Channel vul…6.5
- CVE-2026-45218Improper Neutralization of Special Elements used in an SQL C…7.7
- CVE-2026-45219Rejected reason: This CVE ID has been rejected or withdrawn …
- CVE-2026-4522Missing authentication for critical function vulnerability i…6.7
- CVE-2026-45220Rejected reason: This CVE ID has been rejected or withdrawn …
- CVE-2026-45222Summarize versions through 0.14.1, fixed in commit 0cfb0fb, …6.9
- CVE-2026-45223Crabbox before 0.9.0 contains an authentication bypass vulne…8.8
- CVE-2026-45224Crabbox before 0.9.0 contains a path traversal vulnerability…7.1
- CVE-2026-45225Heym before 0.0.21 contains a path traversal vulnerability i…7.6
- CVE-2026-45226Heym before 0.0.21 contains an authorization bypass vulnerab…7.6
- CVE-2026-45227Heym before 0.0.21 contains a sandbox escape vulnerability i…8.8
Are you affected by CVE-2026-45221?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
