CVE-2026-68955
Received Received - Intake

DLL Hijacking Vulnerability in Rakuten Kobo Desktop Application

Vulnerability report for CVE-2026-68955, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-14

Last updated on: 2026-09-14

Assigner: JPCERT/CC

Description

The installer for Rakuten Kobo Desktop Application (Windows version) insecurely loads Dynamic Link Libraries. If there is a crafted DLL at the same directory when invoking the affected installer, arbitrary code may be executed with the privileges of the user who performed the installation.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-14
Last Modified
2026-09-14
Generated
2026-09-14
AI Q&A
2026-09-14
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
rakuten kobo_desktop_application *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-427 The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The vulnerability in the Rakuten Kobo Desktop Application installer for Windows involves insecure loading of Dynamic Link Libraries (DLLs). If a malicious DLL is placed in the same directory as the installer, it may be loaded and executed with the privileges of the user running the installer.

Detection Guidance

Check for the presence of the vulnerable Kobo Desktop installer in your system by searching for files modified before July 15, 2026. Inspect directories where installers are typically stored for unexpected DLL files. Use antivirus software to scan for malicious DLLs in installer directories.

Impact Analysis

This vulnerability could allow an attacker to execute arbitrary code on your system with your user privileges if you run an affected installer in a directory containing a malicious DLL. This could lead to malware installation, data theft, or further compromise of your system.

Mitigation Strategies

Delete any Kobo Desktop installer files downloaded before July 15, 2026. Download and install the latest version from the official Kobo website. Ensure your system and antivirus software are up to date.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-68955. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart