CVE-2026-45221
Received Received - Intake

Privilege Escalation in Konga via Malicious OpenSSL Files

Vulnerability report for CVE-2026-45221, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-01

Last updated on: 2026-09-01

Assigner: VulnCheck

Description

Konga before 2.1.0 contains a privilege escalation vulnerability that allows low-privileged local attackers to execute arbitrary code by planting attacker-controlled OpenSSL configuration or library files in a hardcoded filesystem path absent from default installations. On Windows, the missing directory resides in a location writable by any authenticated local user, enabling attackers to create the directory and place malicious files that execute at the privilege level of the user or service account that launches Konga, facilitating privilege escalation.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-01
Last Modified
2026-09-01
Generated
2026-09-02
AI Q&A
2026-09-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
heroku konga to 2.1.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-427 The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-45221 is a privilege escalation vulnerability in Konga versions before 2.1.0. It allows low-privileged local attackers to execute arbitrary code by placing malicious OpenSSL configuration or library files in a hardcoded filesystem path. On Windows, this directory is writable by any authenticated local user, enabling attackers to create it and insert malicious files that execute at the privilege level of the Konga user or service account.

Detection Guidance

Check for the presence of the hardcoded OpenSSL directory path on Windows systems where Konga is installed. Look for directories writable by any authenticated local user that may contain OpenSSL configuration or library files. Inspect Konga service accounts and user permissions to identify potential privilege escalation paths.

Impact Analysis

This vulnerability allows attackers with local access to escalate privileges and execute arbitrary code on systems running vulnerable Konga versions. It could lead to unauthorized system access, data theft, or further network compromise depending on the privileges of the Konga service account.

Compliance Impact

This vulnerability could violate compliance requirements by enabling unauthorized access to sensitive data or systems. GDPR and HIPAA require protection against unauthorized access and privilege escalation, which this flaw facilitates. Organizations using vulnerable Konga versions may face compliance violations and potential penalties.

Mitigation Strategies

Upgrade Konga to version 2.1.0 or later to address the vulnerability. Remove write permissions for non-privileged users from directories where Konga or OpenSSL files reside. Monitor for unauthorized file creation in system directories and review service account permissions to limit privilege escalation risks.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-45221. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart