TL;DR
Full technical details and a proof-of-concept are now public for CVE-2026-85714, a CVSS 9.1 Stirling PDF RCE flaw. An authenticated admin can upload a crafted database file and run commands on the server. Version 2.13.2 fixes the bug.
- CVE: CVE-2026-85714 R
- CVSS: 9.1 (Critical · CVSSv3)
- Summary: Summary An authenticated admin can upload a crafted `.sql` file to `POST /api/v1/database/import-database` that executes arbitrary OS commands on the server, with no Java compilation required. The root cause is `validateSqlContent()`, a…
- Status: No confirmed exploitation yet
- Action: See vendor advisory
Track every CVE that hits your stack the moment it's exploited.
Get free email alertsWhy It Matters
Stirling PDF is a popular open-source tool for editing, signing, and converting PDFs. Many teams self-host it so sensitive documents never leave their servers. A server takeover, therefore, puts those very files at risk.
The GitHub advisory describes the attack chain in full. That public write-up lowers the bar for attackers. Even so, no source has reported exploitation in the wild yet.
How the Attack Works
The flaw sits in the database import endpoint. It relies on a keyword allowlist to screen uploaded SQL. However, that check is too shallow. The advisory calls it “a structurally insufficient whitelist” that the H2 database engine “trivially bypasses.”
In short, an admin-supplied script can mix blocked actions into statements that look allowed. The H2 engine then runs powerful built-in functions during import. As a result, the attacker can read files and run OS commands as the application user. No Java compilation is needed.
The entry point requires an authenticated admin account. It also needs the default H2 database with security mode on.
Affected Versions
- Stirling PDF 2.13.2 and earlier, up to and including 2.11.0, are vulnerable.
- Only deployments using the default H2 database with DOCKER_ENABLE_SECURITY set to true are affected.
The advisory notes this is a bypass of an earlier fix for a related issue. The old keyword-list defense could not be made safe by simply adding more keywords.
Patch and Mitigation Steps
Admins should upgrade to version 2.13.2, as the Stirling PDF GHSA-mrr8-934j-4g8m advisory advises. Until then, take these steps:
- Restrict access to the database import feature and the admin panel.
- Review admin accounts and remove any you do not recognize.
- Consider an external database instead of the default H2 setup.
- Keep the Stirling PDF instance off the public internet.
Because this Stirling PDF RCE now has a public PoC, teams should patch quickly. An exposed, unpatched server should be treated as at risk.
Support Our Threat Intelligence
Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!