Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 13 Apr 2026 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Pdfding
Pdfding pdfding |
|
| CPEs | cpe:2.3:a:pdfding:pdfding:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Pdfding
Pdfding pdfding |
Fri, 03 Apr 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 02 Apr 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mrmn2
Mrmn2 pdfding |
|
| Vendors & Products |
Mrmn2
Mrmn2 pdfding |
Wed, 01 Apr 2026 02:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | PdfDing is a selfhosted PDF manager, viewer and editor offering a seamless user experience on multiple devices. Prior to version 1.7.1, check_shared_access_allowed() validates only session existence — it does not check SharedPdf.inactive (expiration / max views) or SharedPdf.deleted. The Serve and Download endpoints rely solely on this function, allowing previously-authorized users to access shared PDF content after expiration, view limit, or soft-deletion. This issue has been patched in version 1.7.1. | |
| Title | PdfDing: Shared PDF Expiration, Max Views, and Deletion Bypass via Serve/Download Endpoints | |
| Weaknesses | CWE-863 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-04-03T16:26:07.467Z
Reserved: 2026-03-30T16:56:30.999Z
Link: CVE-2026-34586
Updated: 2026-04-03T16:26:03.588Z
Status : Analyzed
Published: 2026-03-31T21:16:31.123
Modified: 2026-04-13T16:53:41.963
Link: CVE-2026-34586
No data.
OpenCVE Enrichment
Updated: 2026-04-14T16:42:16Z