Missing authentication in initial setup functionality left exposed after initial setup is completed in GBIF Integrated Publishing Toolkit versions before 3.3.4 allows remote authenticated attackers to gain administrative control via authentication bypass
Metrics
Affected Vendors & Products
References
History
Fri, 21 Aug 2026 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Gbif
Gbif integrated Publishing Toolkit |
|
| Vendors & Products |
Gbif
Gbif integrated Publishing Toolkit |
Tue, 18 Aug 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 18 Aug 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Missing authentication in initial setup functionality left exposed after initial setup is completed in GBIF Integrated Publishing Toolkit versions before 3.3.4 allows remote authenticated attackers to gain administrative control via authentication bypass | |
| Title | Authentication bypass in Integrated Publishing Toolkit | |
| Weaknesses | CWE-306 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: Mandiant
Published: 2026-08-18T17:41:34.141Z
Updated: 2026-08-18T19:28:29.527Z
Reserved: 2026-08-07T22:38:10.919Z
Link: CVE-2026-71878
Updated: 2026-08-18T19:28:26.736Z
Status : Received
Published: 2026-08-18T18:19:32.817
Modified: 2026-08-18T20:17:25.053
Link: CVE-2026-71878
No data.