A vulnerability labeled as critical has been found in RRWO Catalyst View Wkhtmltopdf up to 0.6.0. Impacted is an unknown function. Such manipulation of the argument page_size/orientation/margins leads to os command injection.
This vulnerability is documented as CVE-2026-16766. The attack can be executed remotely. There is not any exploit available.
The affected component should be upgraded.