Insecure Direct Object Reference in TestLink by TestLinkOpenSource TRMS
CVE-2026-70561

7.1HIGH

Key Information:

Status
Vendor
CVE Published:
7 August 2026

What is CVE-2026-70561?

TestLink versions up to 1.9.20 possess a vulnerability allowing authenticated users, including those with low privileges, to access restricted attachments. By manipulating attachment IDs via the attachmentdownload.php handler, attackers can bypass authorization checks and retrieve files from private projects, compromising sensitive information such as test specifications and requirements documents. This vulnerability undermines the project-specific access control mechanisms, enabling unauthorized exposure of files across the TestLink installation.

Affected Version(s)

TestLink 0 <= 1.9.20

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

George Chen
.