{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3akongakonga/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:konga:konga:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.8,"id":"CVE-2026-45221"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Konga (\u003c 2.1.0)"],"_cs_severities":["high"],"_cs_tags":["vulnerability","privilege-escalation","windows"],"_cs_type":"advisory","_cs_vendors":["Konga"],"content_html":"\u003cp\u003eKonga versions prior to 2.1.0 are susceptible to a privilege escalation vulnerability on Windows systems. The application attempts to load OpenSSL configuration or library files from a specific filesystem path that is absent by default in standard installations. Because this target directory resides in a location writable by any authenticated local user, a malicious actor can pre-create the directory and place crafted OpenSSL configuration or library files within it. When the Konga application or associated service is executed, it prioritizes loading these attacker-controlled files from the planted path. This results in the execution of arbitrary code with the privileges of the user or service account running the application, potentially leading to full system compromise if the service operates with elevated permissions.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows a local attacker with low-privileged access to escalate their permissions to the level of the Konga application process. In environments where Konga services run as elevated service accounts, this can lead to full administrative control over the host system. This vulnerability affects all Konga deployments on Windows platforms prior to version 2.1.0.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade Konga to version 2.1.0 or later immediately to resolve the insecure library loading behavior.\u003c/li\u003e\n\u003cli\u003eImplement monitoring for the creation of directories within application-specific paths or known high-risk writeable locations by non-administrative users.\u003c/li\u003e\n\u003cli\u003eAudit Windows service configurations to ensure that services running with elevated privileges are not susceptible to DLL hijacking or library loading vulnerabilities.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-01T21:08:17Z","date_published":"2026-09-01T21:08:17Z","id":"https://feed.craftedsignal.io/briefs/2026-09-konga-privilege-escalation/","summary":"Konga versions before 2.1.0 are vulnerable to privilege escalation on Windows via an insecure library loading path that allows low-privileged local users to execute arbitrary code.","title":"Privilege Escalation in Konga via Insecure Library Loading","url":"https://feed.craftedsignal.io/briefs/2026-09-konga-privilege-escalation/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:konga:konga:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}