Detection and response notes for CVE-2026-85714
Vulnerability overview
CVE-2026-85714 is a CVSS 9.1 remote code execution vulnerability in Stirling PDF, resolved in version 2.13.2 and documented in GHSA-mrr8-934j-4g8m. Technical details and a proof-of-concept are public, no exploitation has been confirmed in the wild, and the flaw bypasses an earlier fix for a related issue.
Mechanism and exploitation conditions
The vulnerable path is POST /api/v1/database/import-database. An authenticated administrator uploads a .sql file, and validateSqlContent() fails to prevent the abuse because its keyword allowlist is structurally insufficient, as the advisory puts it. The H2 engine bypasses the check, and built-in functions executed during import reach the operating system. The attacker needs an authenticated admin session, a deployment on the default H2 database with security mode enabled, and access to the endpoint. No Java compilation is involved.
Impact
The result is command execution in the context of the application user, with file reads and command execution available. For detection planning, the relevant moment is the database import action itself, which is an administrative operation that should be both rare and logged.
Affected products and scope
Stirling PDF 2.13.2 and earlier are affected, up to and including 2.11.0. Only the default H2 deployment with security mode enabled is in scope.
Exposure context
ZoomEye returned 12,644 assets for title="Stirling PDF" and 15,105 for http.body="Stirling PDF". These counts cover discoverable product instances rather than verified vulnerable hosts, so treat them as context for prioritising your own assets.
Remediation and mitigations
Patch to 2.13.2. For response work, review who has administrator rights, restrict the database import feature and the admin panel, and remove accounts that should not exist. Retain logs covering the period before the patch so any earlier import activity can be examined. Where the default H2 database is not required, replace it with an external database, and keep the instance off the public internet. An exposed unpatched server warrants a compromise assessment while the proof-of-concept is public.
References
- Stirling PDF RCE CVE-2026-85714: Details and PoC Publicly Disclosed — source for the CVE identifier, CVSS 9.1 rating, vulnerable endpoint, root cause, affected versions, mitigations and advisory GHSA-mrr8-934j-4g8m.
Top comments (0)