Critical RCE Vulnerabilities in Gotenberg Exposed
Article Content
- •CVE-2026-40281 and CVE-2026-42589 allow unauthenticated RCE in Gotenberg versions ≤ 8.30.1.
- •Public exploit released on October 2, 2026, enables command injection and interactive shell access.
- •Organizations must upgrade to Gotenberg version 8.31.0 or later to mitigate these vulnerabilities.
Recent reports reveal critical unauthenticated remote code execution (RCE) vulnerabilities in Gotenberg versions 8.30.1 and earlier, specifically CVE-2026-40281 and CVE-2026-42589. These vulnerabilities allow attackers to inject commands via crafted metadata values sent to the /forms/pdfengines/metadata/write endpoint without requiring authentication. A proof-of-concept exploit was publicly released on October 2, 2026, enabling detection, single-command execution, and interactive shell access against vulnerable instances. Organizations using affected Gotenberg deployments are urged to upgrade to version 8.31.0 or later to mitigate these risks. The vulnerabilities were disclosed earlier this year, with CVE-2026-40281 receiving a CVSS score of 10.0, indicating a critical severity level. Both vulnerabilities exploit weaknesses in the metadata handling process of Gotenberg, which is a Docker-powered API for converting documents to PDF.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track Gotenberg and CVE-2026-40281 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
Which versions of Gotenberg are affected?
What is the severity of these vulnerabilities?
What should organizations do to protect themselves?
Continue Reading
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited Citrix disclosed two critical zero-day vulnerabilities, CVE-2026-88771 and CVE-2026-88772, affecting NetScaler ADC and Gateway systems, which are being actively exploited. Both vulnerabilities have a CVSS score of 9.5 and allow unauthenticated attackers to execute arbitrary commands remotely. CVE-2026-88771 arises…
Critical Authentication Bypass in Cisco Catalyst SD-WAN Manager Exploited On September 30, 2026, Cisco disclosed a critical vulnerability (CVE-2026-76504) in the Catalyst SD-WAN Manager that allows unauthenticated remote attackers to bypass authentication and gain admin-level access to the system. This flaw stems from improper handling of URI encoding in HTTP requests, enabling attackers to…