{
  "id": "CVE-2026-45221",
  "url": "https://spydr.io/cve/CVE-2026-45221",
  "published": "2026-09-01T20:17:14.680Z",
  "modified": "2026-09-08T20:18:59.270Z",
  "score": 8.5,
  "severity": "high",
  "cvss_version": "4.0",
  "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
  "score_source": "vulncheck.com",
  "epss": 0.00173,
  "epss_percentile": 0.0614,
  "exploited": false,
  "kev": null,
  "ssvc_exploitation": "none",
  "vendors": [
    "EASYBYTE Software"
  ],
  "products": [
    "EASYBYTE Software Konga"
  ],
  "cwes": [
    "CWE-427"
  ],
  "description": "Konga before 2.1.0 contains a privilege escalation vulnerability that allows low-privileged local attackers to execute arbitrary code by planting attacker-controlled OpenSSL configuration or library files in a hardcoded filesystem path absent from default installations. On Windows, the missing directory resides in a location writable by any authenticated local user, enabling attackers to create the directory and place malicious files that execute at the privilege level of the user or service account that launches Konga, facilitating privilege escalation.",
  "status": "Deferred",
  "score_type": "Secondary",
  "scores": {
    "cvss_v40": 8.5,
    "cvss_v31": 7.8,
    "cvss_v30": null
  },
  "references": [
    {
      "url": "https://public.easybyte.it/downloads/archive/2.1.0",
      "tags": []
    },
    {
      "url": "https://www.easybyte.it/",
      "tags": []
    },
    {
      "url": "https://www.vulncheck.com/advisories/konga-privilege-escalation-via-hardcoded-openssl-path",
      "tags": []
    }
  ],
  "nvd_url": "https://nvd.nist.gov/vuln/detail/CVE-2026-45221",
  "covered_in": [],
  "attribution": [
    {
      "source": "NVD",
      "url": "https://nvd.nist.gov",
      "notice": "This product uses data from the NVD API but is not endorsed or certified by the NVD."
    },
    {
      "source": "CISA KEV",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "notice": "Known exploited vulnerabilities from the CISA KEV catalog."
    },
    {
      "source": "FIRST EPSS",
      "url": "https://www.first.org/epss",
      "notice": "Exploit prediction scores from FIRST EPSS."
    }
  ]
}
