DEV Community

yutianle
yutianle

Posted on

Detection and response notes for CVE-2026-85714

Detection and response notes for CVE-2026-85714

Vulnerability overview

CVE-2026-85714 is a CVSS 9.1 remote code execution vulnerability in Stirling PDF, resolved in version 2.13.2 and documented in GHSA-mrr8-934j-4g8m. Technical details and a proof-of-concept are public, no exploitation has been confirmed in the wild, and the flaw bypasses an earlier fix for a related issue.

Mechanism and exploitation conditions

The vulnerable path is POST /api/v1/database/import-database. An authenticated administrator uploads a .sql file, and validateSqlContent() fails to prevent the abuse because its keyword allowlist is structurally insufficient, as the advisory puts it. The H2 engine bypasses the check, and built-in functions executed during import reach the operating system. The attacker needs an authenticated admin session, a deployment on the default H2 database with security mode enabled, and access to the endpoint. No Java compilation is involved.

Impact

The result is command execution in the context of the application user, with file reads and command execution available. For detection planning, the relevant moment is the database import action itself, which is an administrative operation that should be both rare and logged.

Affected products and scope

Stirling PDF 2.13.2 and earlier are affected, up to and including 2.11.0. Only the default H2 deployment with security mode enabled is in scope.

Exposure context

ZoomEye returned 12,644 assets for title="Stirling PDF" and 15,105 for http.body="Stirling PDF". These counts cover discoverable product instances rather than verified vulnerable hosts, so treat them as context for prioritising your own assets.

Remediation and mitigations

Patch to 2.13.2. For response work, review who has administrator rights, restrict the database import feature and the admin panel, and remove accounts that should not exist. Retain logs covering the period before the patch so any earlier import activity can be examined. Where the default H2 database is not required, replace it with an external database, and keep the instance off the public internet. An exposed unpatched server warrants a compromise assessment while the proof-of-concept is public.

References

Top comments (0)