CVE-2023-26987: Konga Project Konga

Medium severity, CVSS 6.5. EPSS: 1.1% chance of exploitation in the next 30 days.

An issue discovered in Konga 0.14.9 allows remote attackers to manipulate user accounts regardless of privilege via crafted POST request.

Affected products

Published 2023-05-01. Last modified 2026-06-17.