Skip to main content
CRITICAL

CVE-2024-22836

CVSS v3

9.8

CRITICAL

EPSS Score

30.0 %

exploit probability, as of 2026-10-03

CISA KEV

No

known exploited

Exploitation

—

SSVC status

Description

An OS command injection vulnerability exists in Akaunting v3.1.3 and earlier. An attacker can manipulate the company locale when installing an app to execute system commands on the hosting server.

Technical details

Published
2024-02-08
Exploit-DB
EDB-51870

Frequently asked questions

What is CVE-2024-22836?

An OS command injection vulnerability exists in Akaunting v3.1.3 and earlier. An attacker can manipulate the company locale when installing an app to execute system commands on the hosting server.

Is CVE-2024-22836 actively exploited?

Active exploitation of CVE-2024-22836 has not been confirmed. Its EPSS score was 30.0% on 2026-10-03, the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2024-22836?

CVE-2024-22836 has a CVSS v3 base score of 9.8 (CRITICAL severity).

Is CVE-2024-22836 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.

No credit card required · 50 free checks/month · Free API key