SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-68955

HIGH · CVSS 7.8 EPSS 0.18%

Source: NVD + CISA KEV + EPSS · Published 2026-09-14 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

The Rakuten Kobo Desktop Application for Windows is vulnerable due to its installer insecurely loading Dynamic Link Libraries (DLLs), allowing an attacker to execute arbitrary code with the privileges of the user running the installation. This high-severity vulnerability poses a significant risk, particularly for users who may inadvertently execute a malicious DLL placed in the same directory as the installer. Organizations and individuals using this application should prioritize patching or mitigating this vulnerability to prevent potential exploitation.

CVE
CVE-2026-68955
Severity
HIGH
CVSS
7.8
EPSS
0.18%
Windows

Original NVD Description

The installer for Rakuten Kobo Desktop Application (Windows version) insecurely loads Dynamic Link Libraries. If there is a crafted DLL at the same directory when invoking the affected installer, arbitrary code may be executed with the privileges of the user who performed the installation.