Insecure Direct Object Reference in TestLink by TestLinkOpenSource TRMS
CVE-2026-70561
7.1HIGH
What is CVE-2026-70561?
TestLink versions up to 1.9.20 possess a vulnerability allowing authenticated users, including those with low privileges, to access restricted attachments. By manipulating attachment IDs via the attachmentdownload.php handler, attackers can bypass authorization checks and retrieve files from private projects, compromising sensitive information such as test specifications and requirements documents. This vulnerability undermines the project-specific access control mechanisms, enabling unauthorized exposure of files across the TestLink installation.
Affected Version(s)
TestLink 0 <= 1.9.20
