CVE-2026-68955 Details
Description
The installer for Rakuten Kobo Desktop Application (Windows version) insecurely loads Dynamic Link Libraries. If there is a crafted DLL at the same directory when invoking the affected installer, arbitrary code may be executed with the privileges of the user who performed the installation.
A vulnerability exists in the installer for the Rakuten Kobo Desktop Application on Windows, prior to July 15, 2026. The installer insecurely loads Dynamic Link Libraries (DLLs), creating a risk that arbitrary code could be executed with the privileges of the user installing the application. This issue arises if a maliciously crafted DLL is placed in the same directory as the installer before it is run.
Users are advised to download the latest version of the Kobo Desktop Application installer from the Kobo website. If an older version of the installer has been downloaded, it should be deleted.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 14, 2026CISA-ADP
Assessed Sep 14, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://help.kobo.com/hc/en-us/articles/42294089837463-Security-Advisory-Kobo-Desktop-App-Installer | [email protected] | AdvisoryRemedyVendor |
| https://jvn.jp/en/jp/JVN18593874/ | [email protected] | AdvisoryRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-427 | Uncontrolled Search Path Element | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Rakuten Kobo Desktop App | < July 15, 2026 |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 14, 2026 | CVE Modified | CISA-ADP |
| Sep 14, 2026 | New CVE Received | [email protected] |
Volerion