Junglewise Threat Intelligence

CVE-2026-92176: pdfforge PDF Architect App object out-of-bounds read remote code execution

CVE-2026-92176 · Severity: high · CVSS 7.8 · Published 2026-09-15

Executive brief

pdfforge PDF Architect is a PDF editing and conversion tool used by professionals. This vulnerability allows attackers to execute arbitrary code on a user's computer by tricking them into opening a malicious PDF file or visiting a malicious webpage. An attacker could gain full control of the affected system to steal sensitive data, install malware, or compromise business operations.

Technical details

The vulnerability is an out-of-bounds buffer read in the handling of App objects within pdfforge PDF Architect. The flaw arises from insufficient validation of user-supplied data when processing App objects, allowing an attacker to read past the end of an allocated buffer. The attack requires user interaction—the target must open a malicious file or visit a malicious page. Successfully exploiting this vulnerability allows an attacker to execute arbitrary code in the context of the PDF Architect process. No patch status is currently documented in the advisory; mitigation is currently limited to restricting use of the product.

Affected products

  • pdfforge PDF Architect

Timeline

  • 2025-11-27: disclosed: Vulnerability reported to vendor
  • 2026-08-31: advisory: Coordinated public release of advisory
  • 2026-09-15: other: Published to NVD

References

Related threats