CVE-2022-51019 Overview
CVE-2022-51019 is an operating system command injection vulnerability [CWE-78] in Akaunting versions prior to 2.1.31. The flaw resides in the module installation and update workflow, where the alias parameter is passed to shell command execution without validation or sanitization. Authenticated users with access to the admin panel can inject shell metacharacters through the alias parameter and execute arbitrary commands on the underlying host. Akaunting is an open-source online accounting application widely deployed for small business finance management.
Critical Impact
Authenticated admin-panel users can execute arbitrary operating system commands with the privileges of the web server process, leading to full server compromise.
Affected Products
- Akaunting versions prior to 2.1.31
- Akaunting app/Jobs/Install/InstallModule.php (module installation flow)
- Akaunting app/Jobs/Install/FinishUpdate.php (module update flow)
Discovery Timeline
- 2026-09-29 - CVE-2022-51019 published to NVD
- 2026-09-29 - Last updated in NVD database
Technical Details for CVE-2022-51019
Vulnerability Analysis
Akaunting exposes module install and update endpoints that internally call the operating system shell to run package operations. The alias request parameter, which identifies the module to install or update, flows into shell command execution without escaping or an allowlist check. An authenticated administrator can supply shell metacharacters (for example ;, &&, |, or backticks) inside the alias value to break out of the intended command and execute additional operating system commands.
Because the vulnerable code runs inside job handlers under app/Jobs/Install/, exploitation results in command execution in the context of the Akaunting worker or web process. Attackers gain the ability to read application secrets, pivot into the database, or establish persistence on the host.
Root Cause
The root cause is unsanitized concatenation of user-controlled input into a shell command string. Both InstallModule.php and FinishUpdate.php in Akaunting 2.1.30 accept the alias parameter and pass it directly to command execution. The application relied on the admin authorization boundary as its only defense, and failed to apply either input validation or a safe process-execution API that separates arguments from the command string.
Attack Vector
Exploitation requires authenticated access to the Akaunting admin panel and network reachability to the application. The attacker issues a request to the module install or update endpoint with a crafted alias value containing shell metacharacters. The malicious payload is appended to the shell command and executed by the underlying operating system. No user interaction is required beyond the attacker's own authenticated session.
// Security patch introducing input validation via a dedicated request class
// Source: https://github.com/akaunting/akaunting/commit/a1792327347a56ea575240b58673b2ece44230da
// app/Http/Controllers/Install/Updates.php
namespace App\Http\Controllers\Install;
use App\Abstracts\Http\Controller;
+use App\Http\Requests\Module\Install as InstallRequest;
use App\Events\Install\UpdateCacheCleared;
use App\Events\Install\UpdateCopied;
use App\Events\Install\UpdateDownloaded;
// app/Http/Controllers/Modules/Item.php
namespace App\Http\Controllers\Modules;
use App\Abstracts\Http\Controller;
+use App\Http\Requests\Module\Install as InstallRequest;
use App\Jobs\Install\CopyFiles;
use App\Jobs\Install\DisableModule;
use App\Jobs\Install\DownloadFile;
The patch introduces the InstallRequest form request class, which validates the alias parameter before it reaches the install and update jobs. See the VulnCheck Advisory: Akaunting OS Command Injection and the vulnerable snippets in FinishUpdate.php and InstallModule.php.
Detection Methods for CVE-2022-51019
Indicators of Compromise
- HTTP POST requests to module install or update routes containing shell metacharacters (;, |, &, backticks, $()) in the alias parameter.
- Child processes of the PHP-FPM or web server user spawning shells (/bin/sh, /bin/bash) with unexpected command lines during module operations.
- Outbound network connections initiated by the Akaunting application user to attacker-controlled infrastructure shortly after module install or update requests.
- New or modified files under the Akaunting modules/ directory that were not part of a legitimate module release.
Detection Strategies
- Inspect web server access logs for requests to /apps/install or /apps/*/update endpoints where the alias field contains non-alphanumeric characters.
- Correlate application logs from Akaunting job workers with process-execution telemetry on the host to identify shell invocations tied to install jobs.
- Deploy a Web Application Firewall rule that blocks shell metacharacters in the alias parameter for module endpoints.
Monitoring Recommendations
- Monitor for the web server process spawning interpreters (sh, bash, python, perl) or network utilities (curl, wget, nc) which is uncommon for a PHP application in steady state.
- Alert on modifications to Akaunting configuration files, .env, and any writable module directories outside of change windows.
- Track admin authentication events and compare admin session activity against module install and update actions.
How to Mitigate CVE-2022-51019
Immediate Actions Required
- Upgrade Akaunting to version 2.1.31 or later, which applies the input-validation patch to the module install and update flows.
- Rotate all Akaunting administrator credentials and any secrets stored in .env, including database credentials and API keys, if the pre-patch version was internet-facing.
- Restrict access to the Akaunting admin panel to trusted networks using firewall rules or a reverse proxy allowlist until patching is complete.
- Review web server and application logs for prior requests to module install or update endpoints containing suspicious alias values.
Patch Information
The fix is available in Akaunting Release 2.1.31. The commit a1792327347a56ea575240b58673b2ece44230da introduces the App\Http\Requests\Module\Install form request class and applies it to both Install\Updates.php and Modules\Item.php controllers so that the alias parameter is validated before reaching shell execution.
Workarounds
- Place the Akaunting admin panel behind an authenticated reverse proxy or VPN to reduce the attacker surface, since exploitation requires an authenticated admin session.
- Deploy a WAF rule that rejects requests to module install and update endpoints when the alias parameter contains characters outside [A-Za-z0-9_-].
- Run the Akaunting PHP process under a least-privilege operating system account with no shell and a restrictive umask to limit post-exploitation impact.
# Example WAF-style filter (ModSecurity) to block shell metacharacters in the alias parameter
SecRule ARGS:alias "@rx [^A-Za-z0-9_\-]" \
"id:1002251019,\
phase:2,\
deny,\
status:400,\
msg:'CVE-2022-51019: Blocked shell metacharacter in Akaunting alias parameter'"
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.