CVE-2022-51019: Akaunting

High severity, CVSS 8.8. EPSS: 1.8% chance of exploitation in the next 30 days.

Akaunting before 2.1.31 contains an OS command injection vulnerability in the module installation and update flow where the alias parameter is passed unvalidated to shell command execution. Authenticated users with admin panel access can inject shell metacharacters into the alias parameter to execute arbitrary commands on the server.

Affected products

  • Akaunting Akaunting: before 2.1.31 (fixed in 2.1.31)

Published 2026-09-29. Last modified 2026-09-29.