---
id: CVE-2026-30276
title: >-
  An arbitrary file overwrite vulnerability in DeftPDF Document Translator v54.0
  allows attackers to overwrite critical internal files via the file import
  process, leading to arbitrary code execution or information exposure.
summary: >-
  An arbitrary file overwrite vulnerability in DeftPDF Document Translator v54.0
  allows attackers to overwrite critical internal files via the file import
  process, leading to arbitrary code execution or information exposure.
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-73
vendor: deftpdf
product: document_translator
affected:
  - document_translator = 54.0
published: '2026-03-31'
updated: '2026-07-24'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-30276'
references:
  - url: 'https://deftpdf.com/'
    label: cve@mitre.org
  - url: 'https://github.com/Secsys-FDU/AF_CVEs/issues/22'
    label: cve@mitre.org
  - url: 'https://secsys.fudan.edu.cn/'
    label: cve@mitre.org
tags:
  - nvd
epss: 0.00828
epssPercentile: 0.5564
ingestedAt: '2026-07-24T20:38:02.234Z'
---

## Overview

An arbitrary file overwrite vulnerability in DeftPDF Document Translator v54.0 allows attackers to overwrite critical internal files via the file import process, leading to arbitrary code execution or information exposure.

## Affected

- `document_translator = 54.0`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
