Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
HighPublic exploit

Arbitrary File Overwrite in Docudepot PDF Reader: PDF Viewer APP File Import Process

IdentifiersCVE-2026-30292CWE-73· External Control of File Name or…

CVE-2026-30292 is an arbitrary file overwrite vulnerability affecting Docudepot PDF Reader: PDF Viewer APP version 1.0.34. According to the provided content, the flaw exists in the application's file import process and allows an attacker to overwrite critical internal files. The weakness is classified as CWE-73. By controlling the file import operation in a way that causes unintended file overwrite of sensitive application-internal targets, an attacker may be able to alter application behavior, expose protected information, or achieve arbitrary code execution depending on which files are replaced and how the application subsequently uses them.

Share:
For your environment

Are you exposed to this one?

Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.

ANALYST BRIEF

Impact, mitigation & remediation

What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.

Impact

What an attacker gets, and what they’ve been doing with it.

Successful exploitation can result in high-impact compromise of confidentiality, integrity, and availability. The provided content states that the vulnerability may lead to arbitrary code execution or information exposure. Because the flaw permits overwrite of critical internal files, an attacker could potentially replace executable or configuration-related files, tamper with application data, or corrupt files required for normal operation, resulting in code execution, disclosure of sensitive information, or application instability and denial of service.

Mitigation

If you can’t patch tonight, do this now.

Until a fixed release is available, avoid using the application's file import functionality with untrusted or externally supplied files. Restrict the app's ability to access attacker-controlled storage locations where possible, and monitor for unexpected modification of application files or abnormal behavior after imports. If feasible in the deployment environment, remove or isolate the vulnerable application from sensitive workflows and data until patched.

Remediation

Patch, then assume compromise.

Upgrade from Docudepot PDF Reader: PDF Viewer APP version 1.0.34 to a vendor-fixed version once available. The vulnerable file import logic should be corrected so that imported files cannot overwrite critical internal files. Remediation should include strict validation and canonicalization of destination paths, enforcement of a fixed safe import directory, prevention of path traversal or arbitrary path selection, and explicit denial of writes to application-internal, executable, configuration, and other sensitive files.
PUBLIC EXPLOITS

Exploits

No public exploits tracked yet. Mallory keeps watching.

VALID 0 / 0 TOTALView more in app

No public exploit code observed for this vulnerability.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets are affected, which adversaries are exploiting it right now, which detections to deploy, and what to do tonight.
Exposure mapping

Query your assets running an affected version, and investigate the blast radius.

Threat actor evidence

Every observed campaign linking this CVE to a named adversary.

Associated malware

Malware families riding this exploit, with evidence and IOCs.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Vendor-by-vendor mapping

Cross-references every affected SKU, including bundled OEM variants.

Social activity2

Community discussion across Reddit, Mastodon, and other social sources.