CVE-2026-57485 – Stirling-PDF

CVSS 8.5 IMPORTANT Zero Day – Immediate Deployment

“A standard user can expose an internal service credential and gain access beyond normal application controls.”

Stirling-PDF before 2.9.0 contains a High-severity credential exposure and privilege escalation flaw in its pipeline endpoint. CVE-2026-57485 allows an authenticated user to retrieve the internal backend API key, impersonate the service account, bypass normal rate limits, and access internal administrative information endpoints. The CVSS score is 8.5, which is High severity.

The issue is fixed in Stirling-PDF 2.9.0. Public proof-of-concept material is available.

Key Details

Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
CWE Classification
CWE-200
Patch this CVE on all your endpoints in under 5 minutes. First 200 endpoints are free forever, scale as needed.