CVE-2022-50938: Contpaqi Contpaq Adminpaq

High severity, CVSS 8.4. EPSS: 0.2% chance of exploitation in the next 30 days.

CONTPAQi AdminPAQ 14.0.0 contains an unquoted service path vulnerability in the AppKeyLicenseServer service running with LocalSystem privileges. Attackers can exploit the unquoted path to inject malicious code in the service binary path, potentially executing arbitrary code with elevated system privileges during service startup.

Affected products

  • Contpaqi Contpaq Adminpaq: version 14.0.0 only

Published 2026-01-13. Last modified 2026-06-17.