Authentication Bypass in GBIF Integrated Publishing Toolkit
CVE-2026-71878
9.2CRITICAL
What is CVE-2026-71878?
A vulnerability in the GBIF Integrated Publishing Toolkit allows remote authenticated attackers to exploit missing authentication mechanisms during the initial setup phase. This oversight permits unauthorized individuals to gain administrative access to sensitive system functionalities post-setup. The issue impacts versions of the toolkit released before 3.3.4, emphasizing the critical need for users to update to the latest version to safeguard their systems against potential exploitation.
Affected Version(s)
Integrated Publishing Toolkit 0 < 3.3.4
