CYBERSECURITY BRIEFING NOTE CVE-2026-33929 is a path traversal vulnerability in the ExtractEmbeddedFiles example component of Apache PDFBox affecting versions 2.0.24 through 2.0.36 and 3.0.0 through 3.0.7. The vulnerability stems from an incomplete remediation of a previously identified path traversal issue (CVE-2026-23907), wherein the patched code fails to properly validate file path separators. This flaw allows an attacker to write files to directories outside the intended restricted directory by exploiting improper pathname limitations. The vulnerability carries a CVSS score of 4.3 (Medium severity) with network-based attack vector, low attack complexity, and low privilege requirements. The impact is limited to integrity compromise with no confidentiality or availability concerns. The relatively low CVSS score reflects the requirement for authenticated access and the localized impact scope of file write operations. There is no evidence of active exploitation in the wild, and the vulnerability is not listed in the Known Exploited Vulnerabilities catalog. However, the issue poses a practical risk to organizations that have incorporated the vulnerable example code into production systems. Apache PDFBox has released patched versions 2.0.37 and 3.0.8, and affected users should prioritize updating while applying the referenced GitHub PR 427 fix as an interim measure if upgrades cannot be immediately deployed.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.0.24, < 2.0.37CPE matchmatch criteria | cpe:2.3:a:apache:pdfbox:*:*:*:*:*:*:*:* | ||
>= 3.0.0, < 3.0.8CPE matchmatch criteria | cpe:2.3:a:apache:pdfbox:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.