STIRLING PDF RCE CVE-2026-85714 has had full technical details and a public proof-of-concept disclosed. The flaw lies in Stirling PDF’s database import endpoint, where an authenticated admin can upload a crafted .sql file to POST /api/v1/database/import-database and cause arbitrary OS commands to run on the server without Java compilation.
The root cause is described as a structurally insufficient keyword whitelist in validateSqlContent(), which the H2 database engine can bypass, allowing an admin-supplied script to embed blocked actions into seemingly allowed statements. When executed, the attacker can read files and run OS commands as the application user. The entry point requires an authenticated admin account and the default H2 database with security mode enabled.
Affected versions and patch guidance are clear: Stirling PDF 2.13.2 and earlier, up to and including 2.11.0, are vulnerable, and only deployments using the default H2 database with DOCKER_ENABLE_SECURITY=true are affected. The advisory notes this bypasses an earlier fix for a related issue, indicating the prior keyword-based defence could not be made safe merely by adding keywords.
The recommended patch is to upgrade to version 2.13.2, with mitigations including restricting access to the database import feature and admin panel, auditing admin accounts, considering an external database, and keeping Stirling PDF off the public internet. The article notes there is currently no confirmed exploitation in the wild, but a public PoC has lowered the bar for attackers and rapid patching is advised.