Description
pdfforge PDF Architect PDF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of pdfforge PDF Architect. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.

The specific flaw exists within the parsing of PDF files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-28673.
Published: 2026-09-15
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Patch
AI Analysis

Impact

The vulnerability is an out-of-bounds write during PDF parsing that can be triggered by specially crafted PDF files. The flaw is captured in CWE-787 and allows a remote attacker to execute arbitrary code in the context of the PDF Architect process once the file is processed. Because the attacker’s code runs with the same privileges as the user running the application, the impact ranges from local escalation to full system compromise.

Affected Systems

Affected software is pdfforge PDF Architect. No specific version information is publicly disclosed, so all installations that are still on older releases may be vulnerable. Users should verify the version they run and check for any available updates from pdfforge.

Risk and Exploitability

The CVSS score of 7.8 indicates high potential impact but user must open a malicious PDF or navigate to a page that serves such a file to the application. EPSS score of < 1% indicates a low likelihood of exploitation and the vulnerability is not in the CISA KEV catalog, but given the remote code execution payload and the lack of a safeguard, the risk remains significant. Attackers would typically employ phishing emails or compromised websites to entice victims into opening the malicious document.

Generated by OpenCVE AI on September 20, 2026 at 14:24 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Install the latest version of PDF Architect, which addresses the out-of-bounds write flaw.
  • Configure PDF Architect to block automatic download and opening of PDFs from untrusted sources or run the application in a sandboxed environment.
  • For users unable to update, scan suspicious PDF files with up-to-date antivirus or sandbox before opening.

Generated by OpenCVE AI on September 20, 2026 at 14:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Pdfforge
Pdfforge pdf Architect
Vendors & Products Pdfforge
Pdfforge pdf Architect

Tue, 15 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Description pdfforge PDF Architect PDF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of pdfforge PDF Architect. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of PDF files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-28673.
Title pdfforge PDF Architect PDF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
Weaknesses CWE-787
References
Metrics cvssV3_0

{'score': 7.8, 'vector': 'CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

Pdfforge Pdf Architect
cve-icon MITRE

Status: PUBLISHED

Assigner: zdi

Published:

Updated: 2026-09-16T03:57:26.339Z

Reserved: 2026-09-15T18:04:39.345Z

Link: CVE-2026-92177

cve-icon Vulnrichment

Updated: 2026-09-15T19:24:23.304Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T19:17:48.130

Modified: 2026-09-16T20:26:50.280

Link: CVE-2026-92177

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T14:30:18Z

Weaknesses