CVE-2026-23907 | Apache PDFBox up to 2.0.36/3.0.7 Example PDComplexFileSpecification.getFilename path traversal
A vulnerability labeled as critical has been found in Apache PDFBox up to 2.0.36/3.0.7. This affects the function PDComplexFileSpecification.getFilename of the component Example. Such manipulation leads to path traversal.
This vulnerability is referenced as CVE-2026-23907. It is possible to launch the attack remotely. No exploit is available.