Skip to content
Critical RCE Vulnerabilities in Gotenberg Exposed

Critical RCE Vulnerabilities in Gotenberg Exposed

First seen 5 Oct 2026, 02:03 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 5, 2026 at 03:03 UTC
  • •CVE-2026-40281 and CVE-2026-42589 allow unauthenticated RCE in Gotenberg versions ≤ 8.30.1.
  • •Public exploit released on October 2, 2026, enables command injection and interactive shell access.
  • •Organizations must upgrade to Gotenberg version 8.31.0 or later to mitigate these vulnerabilities.

Recent reports reveal critical unauthenticated remote code execution (RCE) vulnerabilities in Gotenberg versions 8.30.1 and earlier, specifically CVE-2026-40281 and CVE-2026-42589. These vulnerabilities allow attackers to inject commands via crafted metadata values sent to the /forms/pdfengines/metadata/write endpoint without requiring authentication. A proof-of-concept exploit was publicly released on October 2, 2026, enabling detection, single-command execution, and interactive shell access against vulnerable instances. Organizations using affected Gotenberg deployments are urged to upgrade to version 8.31.0 or later to mitigate these risks. The vulnerabilities were disclosed earlier this year, with CVE-2026-40281 receiving a CVSS score of 10.0, indicating a critical severity level. Both vulnerabilities exploit weaknesses in the metadata handling process of Gotenberg, which is a Docker-powered API for converting documents to PDF.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-05-06
CVE-2026-40281 published
CVE-2026-40281, a critical RCE vulnerability, was disclosed with a CVSS score of 10.0.
github.com
2026-05-14
CVE-2026-42589 published
CVE-2026-42589 was published, also rated critical with a CVSS score of 9.8.
Sploitus
2026-10-02
Public exploit released
A proof-of-concept exploit for CVE-2026-40281 was made publicly available, enabling various attack methods.
X
2026-10-03
Sploitus article published
Sploitus published detailed information about the exploit and its capabilities for Gotenberg vulnerabilities.
Sploitus

More articles in this cluster (3)

Following this threat?

Track Gotenberg and CVE-2026-40281 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

Which versions of Gotenberg are affected?
Gotenberg versions 8.30.1 and earlier are affected by the vulnerabilities.
What is the severity of these vulnerabilities?
CVE-2026-40281 has a CVSS score of 10.0, marking it as critical.
What should organizations do to protect themselves?
Organizations should upgrade to Gotenberg version 8.31.0 or later to mitigate the vulnerabilities.