Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

Stirling-PDF CVE-2026-85714 is a critical, authenticated-admin remote code execution vulnerability. Stirling-Tools lists versions up to and including 2.11.0 as affected and v2.13.2 as patched. The vendor’s advisory, published October 2, 2026, describes a path from an uploaded SQL file to operating-system command execution, but the reported attack requires an authenticated administrator and a particular H2 database configuration.

What does CVE-2026-85714 allow an attacker to do?

The Stirling-Tools advisory says an authenticated administrator can upload a crafted .sql file to POST /api/v1/database/import-database. The vendor describes the file being processed by H2 during backup verification and then against the production database. Its summary states: “An authenticated admin can upload a crafted .sql file to POST /api/v1/database/import-database that executes arbitrary OS commands on the server, with no Java compilation required.” The statement is from the Stirling-Tools/Stirling-PDF GitHub security advisory published by Frooodle on October 2, 2026; the page does not identify a human speaker or role. Read the vendor advisory.

This is not described as unauthenticated remote code execution. The advisory’s prerequisites include administrator access and its stated H2/security configuration; it does not demonstrate that an arbitrary remote installation can be compromised without those conditions.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How does the reported exploit chain work?

The SQL filter can be bypassed through H2 behavior

According to the advisory, Stirling-PDF’s validateSqlContent() normalizes the submitted SQL, splits it at semicolons, and accepts statements that contain allowed keywords. The filtering does not account for H2 built-in functions and alias creation used as side effects. As a result, a statement can include an allowed keyword while also invoking a dangerous function. The vendor names H2 features including FILE_READ, CSVWRITE, LINK_SCHEMA, and Java method aliases in its explanation.

#1 Best Overall

File writes lead to code execution in a later subprocess

The vendor’s documented chain uses H2 to create a directory and write Python and .pth files. It then triggers a later conversion subprocess using unoconvert, causing Python to load the planted module. The reported result is operating-system-level code execution with the permissions of the Stirling-PDF JVM process. These mechanics and the PoC are described by the vendor; they have not been independently reproduced here.

Which Stirling-PDF versions and configurations are affected?

The vendor identifies versions <= 2.11.0 as affected and v2.13.2 as patched. It says affected deployments use the default H2 database with security mode enabled, configured with DOCKER_ENABLE_SECURITY=true. Check both the deployed version and database/security settings rather than inferring exposure from the product name alone.

Vendor advisory status Version or configuration What it means
Affected Versions <= 2.11.0 Listed by the vendor as affected; the stated configuration condition is default H2 with security mode enabled.
Patched v2.13.2 Version identified by the vendor as patched.
Not specified in the advisory’s stated boundary Versions 2.11.1 through 2.13.1 The advisory does not establish their status in the affected-version statement; consult the vendor advisory or obtain confirmation rather than assuming either way.

All version and configuration statements in this table are from the October 2, 2026 vendor advisory.

What does the public PoC show?

The official advisory includes a proof of concept. Its listed prerequisites are a Stirling-PDF instance using default H2 with security mode enabled, default administrator credentials, and Python 3 with the requests package. At a high level, the demonstration uploads SQL, triggers conversion, and verifies the resulting output. The advisory documents those steps and the exploit chain, but this article does not reproduce a turnkey payload. The PoC’s publication is not evidence that the issue has been exploited in the wild.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What should Stirling-PDF administrators do?

  1. Identify the deployed release. Compare the exact installed version with the vendor’s affected boundary; do not treat versions omitted from that boundary as confirmed affected or confirmed safe.
  2. Check the relevant configuration. Determine whether the deployment uses the default H2 database and whether DOCKER_ENABLE_SECURITY=true.
  3. Upgrade if affected. The vendor lists v2.13.2 as the fix. Upgrade to that version or a later vendor-supported release confirmed to include the fix, and consult the advisory for release-specific details.
  4. Assess administrator access. Because the reported entry point requires an authenticated administrator, review who can use administrator credentials and investigate suspicious database-import or conversion activity as part of your incident-response process.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How severe is the vulnerability, and is exploitation confirmed?

Stirling-Tools rates CVE-2026-85714 Critical, with CVSS 3.1 score 9.1 and vector CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H. The PR:H component reflects the high-privilege prerequisite in the score. The official advisory index also lists “Remote Code Execution via H2” as Critical and dates it October 2, 2026. Available advisory information does not establish in-the-wild exploitation or the number of exposed deployments. Feedly also has a CVE page, but its severity is identified as an estimate; the vendor’s rating is the primary severity assessment here: Feedly CVE-2026-85714.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.