AUGUST 25, 2026
Live Feed
Back to database
Case File

CVE-2026-13126

HIGH · CVSS 7.8 EPSS 0.16%

Source: NVD + CISA KEV + EPSS · Published 2026-07-08 · Last synced 2026-08-07

CyberRota Analysis

AI-Generated

The vulnerability affects Java applications that process embedded JavaScript in PDFs, leading to potential crashes when attempting to write to invalid pop-up annotations after page deletion. This can disrupt service availability and may expose sensitive data during the crash. Organizations utilizing Java for PDF processing should prioritize addressing this issue to mitigate operational risks.

CVE
CVE-2026-13126
Severity
HIGH
CVSS
7.8
EPSS
0.16%
Java

Original NVD Description

The embedded JavaScript in the PDF deleted the pages, making the object invalid. The application attempted to perform a write operation on the invalid pop-up annotations, resulting in the program crashing.

Related CVEs

Other vulnerabilities affecting the same vendor(s)