Authentication Bypass in GBIF Integrated Publishing Toolkit
CVE-2026-71878

9.2CRITICAL

Key Information:

Vendor

Gbif

Vendor
CVE Published:
18 August 2026

What is CVE-2026-71878?

A vulnerability in the GBIF Integrated Publishing Toolkit allows remote authenticated attackers to exploit missing authentication mechanisms during the initial setup phase. This oversight permits unauthorized individuals to gain administrative access to sensitive system functionalities post-setup. The issue impacts versions of the toolkit released before 3.3.4, emphasizing the critical need for users to update to the latest version to safeguard their systems against potential exploitation.

Affected Version(s)

Integrated Publishing Toolkit 0 < 3.3.4

References

CVSS V4

Score:
9.2
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.