CVE-2026-16766 is a critical shell command injection vulnerability discovered in Catalyst::View::Wkhtmltopdf, a Perl module used to render PDF output within the Catalyst web framework. All versions prior to 0.6.1 are affected, with exploitation possible remotely via unsanitised PDF render options including page_size, orientation, and margins parameters. The CPAN Security Group disclosed the vulnerability on 25 July 2026 alongside the release of the patched version.
The flaw permits an attacker to inject arbitrary OS commands through manipulated render option arguments passed to the underlying wkhtmltopdf binary. Because Catalyst is a widely used Perl web application framework, any application that exposes PDF generation functionality to user-controlled input is potentially at risk of full remote code execution on the hosting server. At time of disclosure, no public exploit code was known to be available, though the attack surface is straightforward and exploitation is considered technically accessible to moderately skilled actors.
Each brief contains detailed narrative, impact assessments, technical analysis, IOCs, and response recommendations — available inside the Deltabridge platform.