CVE-2026-57485

8.5

Stirling-Tools · Stirling-PDF

Stirling-PDF versions prior to 2.9.0 contain vulnerabilities related to the exposure of sensitive information and insufficient protection of credentials, potentially allowing unauthorized data access.

Executive summary

Stirling-PDF is vulnerable to sensitive information exposure and credential mishandling, which could allow authenticated attackers to access private data or compromise system security.

Vulnerability

The application fails to adequately protect credentials and sensitive system information from access by authenticated users. This flaw allows an attacker with low privileges to gain unauthorized access to data that should be restricted, potentially leading to a broader compromise of the application context.

Business impact

With a CVSS score of 8.5, this vulnerability represents a significant risk to data privacy. Successful exploitation could allow attackers to harvest sensitive credentials or documents processed by the application, leading to a breach of sensitive organizational information and potential lateral movement within the environment.

Remediation

Immediate Action: Update the Stirling-PDF application to version 2.9.0 or later to resolve the underlying credential and information exposure flaws.

Proactive Monitoring: Review application access logs to identify unusual patterns of data retrieval or attempts to access configuration and credential files by non-administrative users.

Compensating Controls: Implement strict access control lists and ensure that the application is not exposed to untrusted networks, minimizing the potential for unauthorized users to reach the vulnerable endpoints.

Exploitation status

Public Exploit Available: No

Analyst recommendation

The severity of this vulnerability necessitates a prompt update to version 2.9.0. Administrators should prioritize this patch to ensure that sensitive documents and system credentials remain protected from unauthorized access by authenticated users.

More Stirling-Tools CVEs