CVE-2026-30291 is a high-severity arbitrary file overwrite vulnerability in Ora Tools PDF Reader ' Reader & Editor APPv4.3.5. This flaw enables attackers to overwrite critical internal files via the file import process. Rated with a CVSS score of 8.4, successful exploitation requires local access and can lead to arbitrary code execution or sensitive information exposure without user interaction. While not currently listed on CISA's Known Exploited Vulnerabilities catalog and lacking public exploit code, it is on a "Hot List" indicating elevated concern, with limited community discussion observed.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| N/A | N/A | n/aCNA affected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.5 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.