CVE-2026-68955: Uncontrolled Search Path Element in Rakuten Kobo Inc. The installer for Rakuten Kobo Desktop Application (Windows version)
The installer for Rakuten Kobo Desktop Application (Windows version) insecurely loads Dynamic Link Libraries. If there is a crafted DLL at the same directory when invoking the affected installer, arbitrary code may be executed with the privileges of the user who performed the installation.
AI Analysis
Technical Summary
The Rakuten Kobo Desktop Application installer for Windows insecurely loads DLLs from its execution directory. This uncontrolled search path element vulnerability allows an attacker to place a crafted DLL alongside the installer, which will be loaded and executed with the user's privileges during installation. This can lead to arbitrary code execution under the context of the installing user.
Potential Impact
An attacker who can place a malicious DLL in the installer's directory can execute arbitrary code with the privileges of the user running the installer. This could lead to full compromise of the user's environment depending on their privileges. The CVSS 3.0 score is 7.8 (high), reflecting the potential for high confidentiality, integrity, and availability impact.
Mitigation Recommendations
No patch or remediation information is provided in the available data. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, users should ensure the installer directory is secure and free of untrusted DLLs before running the installer.
CVE-2026-68955: Uncontrolled Search Path Element in Rakuten Kobo Inc. The installer for Rakuten Kobo Desktop Application (Windows version)
Description
The installer for Rakuten Kobo Desktop Application (Windows version) insecurely loads Dynamic Link Libraries. If there is a crafted DLL at the same directory when invoking the affected installer, arbitrary code may be executed with the privileges of the user who performed the installation.
CVSS v3.0
Score 7.8high
Affected software
Rakuten Kobo Inc.
The installer for Rakuten Kobo Desktop Application (Windows version)
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Rakuten Kobo Desktop Application installer for Windows insecurely loads DLLs from its execution directory. This uncontrolled search path element vulnerability allows an attacker to place a crafted DLL alongside the installer, which will be loaded and executed with the user's privileges during installation. This can lead to arbitrary code execution under the context of the installing user.
Potential Impact
An attacker who can place a malicious DLL in the installer's directory can execute arbitrary code with the privileges of the user running the installer. This could lead to full compromise of the user's environment depending on their privileges. The CVSS 3.0 score is 7.8 (high), reflecting the potential for high confidentiality, integrity, and availability impact.
Mitigation Recommendations
No patch or remediation information is provided in the available data. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, users should ensure the installer directory is secure and free of untrusted DLLs before running the installer.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- jpcert
- Date Reserved
- 2026-08-04T12:25:41.796Z
- Cvss Version
- 3.0
- State
- PUBLISHED
Threat ID: 6aa79bfd55bf5e2cf5ac9d66
Added to database: 09/14/2026, 07:02:21 UTC
Last enriched: 09/14/2026, 07:33:23 UTC
Last updated: 09/14/2026, 22:11:26 UTC
Views: 5
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.