Critical severity9.8NVD Advisory· Published Aug 16, 2023· Updated Jun 17, 2026
CVE-2023-39846
CVE-2023-39846
Description
An issue in Konga v0.14.9 allows attackers to bypass authentication via a crafted JWT token.
Affected products
3- Konga/Kongadescription
Patches
Vulnerability mechanics
References
1- abyssaler.github.io/post/konga%20Unauthorized%20accessnvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.