Authorization Bypass in Typemill Media File Download Route by Typemill
CVE-2026-71518
8.7HIGH
What is CVE-2026-71518?
An authorization bypass vulnerability exists in Typemill versions prior to 2.26.0, specifically affecting the media file download route. This flaw allows unauthorized users to access restricted files by submitting cleverly crafted path-equivalent URL variants. Attackers can exploit normalized path forms, including dot-slash prefixes, double slashes, or percent-encoded sequences, enabling them to circumvent role-based restriction checks. This results in the potential for unauthenticated file downloads, compromising sensitive data without requiring valid credentials.
Affected Version(s)
typemill 0
