A vulnerability labeled as critical has been found in RRWO Catalyst View Wkhtmltopdf up to 0.6.0. Impacted is an unknown function. Such manipulation of the argument page_size/orientation/margins leads to os command injection.

This vulnerability is documented as CVE-2026-16766. The attack can be executed remotely. There is not any exploit available.

The affected component should be upgraded.