Medium severity6.5NVD Advisory· Published May 1, 2023· Updated Jun 17, 2026
CVE-2023-26987
CVE-2023-26987
Description
An issue discovered in Konga 0.14.9 allows remote attackers to manipulate user accounts regardless of privilege via crafted POST request.
Affected products
3- cpe:2.3:a:konga_project:konga:0.14.9:-:*:*:*:*:*:*
- Konga/Kongadescription
Patches
Vulnerability mechanics
References
2- docs.google.com/document/d/14DYoZfKN__As8gBXMFae7wChKJXpmbuUdMn2Gf803LwnvdExploitThird Party Advisory
- docs.google.com/document/d/14DYoZfKN__As8gBXMFae7wChKJXpmbuUdMn2Gf803Lw/editnvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.