Executive brief
Konga is business management software used by small and medium enterprises to track accounting, inventory, sales, and other operations across multiple users and platforms. A privilege escalation vulnerability in versions before 2.1.0 allows low-privileged local attackers to plant malicious OpenSSL configuration or library files in a missing but writable directory, which are then loaded when Konga launches, enabling arbitrary code execution at the privilege level of the Konga user or service account. On Windows systems, any authenticated local user can exploit this by creating the directory and placing malicious files.
Technical details
The vulnerability is a local privilege escalation arising from unsafe library loading. Konga references OpenSSL configuration or library files from a hardcoded filesystem path that is absent from default installations. On Windows, this missing directory resides in a location (typically a user-writable path or a path in the application directory) that is writable by any authenticated local user. An attacker with local access can create this directory and place malicious OpenSSL configuration files or libraries within it. When Konga launches, it loads these attacker-controlled files at the privilege level of the user or service account running Konga, resulting in arbitrary code execution. The attack requires local filesystem access but no authentication to Konga itself. This issue is fixed in Konga 2.1.0.
Affected products
- EasyByte Konga before 2.1.0
Timeline
- 2026-09-01: disclosed
- 2026-09-15: patched: Version 2.1.0 released with fix