CVE-2026-12057 - CERT CVE
ID CVE-2026-12057
Sažetak When the application executes the JavaScript script embedded in the PDF within the sandbox, it fails to intercept some dangerous interfaces, which allows remote scripts to be loaded, resulting in arbitrary code execution.
Reference
CVSS
Base: 8.6
Impact: 6.0
Exploitability:1.8
Pristup
VektorSloženostAutentikacija
LOCAL LOW NONE
Impact
PovjerljivostCjelovitostDostupnost
HIGH HIGH HIGH
CVSS vektor CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Zadnje važnije ažuriranje 16-06-2026 - 16:43
Objavljeno 15-06-2026 - 12:16