A vulnerability classified as critical was found in Apache PDFBox Examples up to 2.0.36/3.0.7. This vulnerability affects unknown code of the component ExtractEmbeddedFiles. The manipulation results in path traversal.

This vulnerability is cataloged as CVE-2026-33929. The attack may be launched remotely. There is no exploit available.

Upgrading the affected component is advised.