Authentication Bypass Vulnerability in GBIF Integrated Publishing Toolkit by GBIF
CVE-2026-71879

9.1CRITICAL

Key Information:

Vendor

Gbif

Vendor
CVE Published:
18 August 2026

What is CVE-2026-71879?

A significant security vulnerability exists in the GBIF Integrated Publishing Toolkit, present in versions prior to 3.3.4. This flaw arises from a lack of proper authentication in the initial setup functionality, leaving the system exposed until the first reboot. This exposure allows remote authenticated attackers to exploit the authentication bypass and potentially gain full administrative control of the application, posing a serious risk to users and data integrity.

Affected Version(s)

Integrated Publishing Toolkit 0 < 3.3.4

References

CVSS V4

Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.