Authorization Bypass in Typemill Media File Download Route by Typemill
CVE-2026-71518

8.7HIGH

Key Information:

Vendor

Typemill

Status
Vendor
CVE Published:
17 August 2026

What is CVE-2026-71518?

An authorization bypass vulnerability exists in Typemill versions prior to 2.26.0, specifically affecting the media file download route. This flaw allows unauthorized users to access restricted files by submitting cleverly crafted path-equivalent URL variants. Attackers can exploit normalized path forms, including dot-slash prefixes, double slashes, or percent-encoded sequences, enabling them to circumvent role-based restriction checks. This results in the potential for unauthenticated file downloads, compromising sensitive data without requiring valid credentials.

Affected Version(s)

typemill 0

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ilhomjon Rustamov
VulnCheck
.