← Back to CVE List
CVE-2026-85714NVD
Vulnerability Summary
Summary An authenticated admin can upload a crafted `.sql` file to `POST /api/v1/database/import-database` that executes arbitrary OS commands on the server, with no Java compilation required. The root cause is `validateSqlContent()`, a structurally insufficient whitelist that H2's built-in function surface trivially bypasses. It splits input by `;` without SQL string context and accepts any fragment containing at least one whitelisted keyword (`INSERT INTO`, `VALUES`, `NULL`, `AS`, `CREATE`, etc.), regardless of what H2 built-in functions the statement invokes. ---
CVSS v3.1 Base Metrics — Score 9.1
Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredHigh
User InteractionNone
ScopeChanged
ConfidentialityHigh
IntegrityHigh
AvailabilityHigh
Affected & Patched Versions
- stirling-software/stirling-pdf <= 2.11.0
- stirling-software/stirling-pdf v2.13.2