CVE-2026-68955

Summary

The installer for Rakuten Kobo Desktop Application (Windows version) insecurely loads Dynamic Link Libraries. If there is a crafted DLL at the same directory when invoking the affected installer, arbitrary code may be executed with the privileges of the user who performed the installation.

Affected Software

VendorProductVersion RangeStatus
Rakuten Kobo Inc.The installer for Rakuten Kobo Desktop Application (Windows version)Versions distributed before 2026-07-15.affected

Weaknesses

  • CWE-427: Uncontrolled Search Path Element

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References