CVE-2026-57485 – Stirling-PDF
CVSS 8.5
IMPORTANT
Zero Day – Immediate Deployment
“A standard user can expose an internal service credential and gain access beyond normal application controls.”
Stirling-PDF before 2.9.0 contains a High-severity credential exposure and privilege escalation flaw in its pipeline endpoint. CVE-2026-57485 allows an authenticated user to retrieve the internal backend API key, impersonate the service account, bypass normal rate limits, and access internal administrative information endpoints. The CVSS score is 8.5, which is High severity.
The issue is fixed in Stirling-PDF 2.9.0. Public proof-of-concept material is available.
Key Details
- Attack Vector
- Network
- Attack Complexity
- Low
- Privileges Required
- Low
- User Interaction
- None
- CWE Classification
- CWE-200
Patch this CVE on all your endpoints in under 5 minutes.
First 200 endpoints are free forever, scale as needed.