AUGUST 30, 2026
Live Feed
Back to database
Case File

CVE-2026-57259

MEDIUM · CVSS 6.5 EPSS 0.22%

Source: NVD + CISA KEV + EPSS · Published 2026-07-08 · Last synced 2026-08-07

CyberRota Analysis

AI-Generated

The vulnerability allows maliciously crafted documents, disguised as PDFs, to bypass strict format validation, enabling attackers to create external entities that can access local files within the user's permission range. This poses a risk of unauthorized data exposure or manipulation. Organizations handling PDF documents, particularly those with sensitive information, should prioritize addressing this vulnerability to mitigate potential data breaches.

CVE
CVE-2026-57259
Severity
MEDIUM
CVSS
6.5
EPSS
0.22%

Original NVD Description

The input file does not need to be strictly in a structurally valid PDF format. Instead, after reviewing the content, the original document disguised as a PDF will be sent to the parser. Malicious documents will construct malicious external entities that, through the protocol, point to local paths, thereby allowing access to any local files within the user's permission range.

Related CVEs

Other vulnerabilities affecting the same vendor(s)