CVE-2026-68955
7.8
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Summary
The installer for Rakuten Kobo Desktop Application (Windows version) insecurely loads Dynamic Link Libraries. If there is a crafted DLL at the same directory when invoking the affected installer, arbitrary code may be executed with the privileges of the user who performed the installation.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Rakuten Kobo Inc. | The installer for Rakuten Kobo Desktop Application (Windows version) | Versions distributed before 2026-07-15. | affected |
Weaknesses
- CWE-427: Uncontrolled Search Path Element
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: none
- Automatable: no
- Technical Impact: total
References
- https://help.kobo.com/hc/en-us/articles/42294089837463-Security-Advisory-Kobo-Desktop-App-Installer
- https://jvn.jp/en/jp/JVN18593874/
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.