CVE-2026-34586 is a medium-severity vulnerability in PdfDing versions prior to 1.7.1, a selfhosted PDF manager. This flaw allows previously authorized users to bypass access restrictions, enabling them to view shared PDF content even after it has expired, reached its view limit, or been soft-deleted, resulting in a high impact on confidentiality. With a CVSS score of 6.5, the vulnerability has a low attack complexity and can be exploited over the network with low privileges. There is currently no evidence of active exploitation, nor are public exploit codes or Metasploit modules available, with minimal community discussion observed.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.7.1CPE matchmatch criteria | cpe:2.3:a:pdfding:pdfding:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.