Missing authentication in initial setup functionality left exposed until first reboot in GBIF Integrated Publishing Toolkit versions before 3.3.4 allows remote authenticated attackers to gain administrative control via authentication bypass
Metrics
Affected Vendors & Products
References
History
Fri, 21 Aug 2026 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Gbif
Gbif integrated Publishing Toolkit |
|
| Vendors & Products |
Gbif
Gbif integrated Publishing Toolkit |
Tue, 18 Aug 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 18 Aug 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Missing authentication in initial setup functionality left exposed until first reboot in GBIF Integrated Publishing Toolkit versions before 3.3.4 allows remote authenticated attackers to gain administrative control via authentication bypass | |
| Title | Authentication bypass in Integrated Publishing Toolkit | |
| Weaknesses | CWE-288 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: Mandiant
Published: 2026-08-18T17:41:48.060Z
Updated: 2026-08-18T19:29:12.627Z
Reserved: 2026-08-07T22:38:10.919Z
Link: CVE-2026-71879
Updated: 2026-08-18T19:29:02.173Z
Status : Received
Published: 2026-08-18T18:19:32.960
Modified: 2026-08-18T20:17:25.180
Link: CVE-2026-71879
No data.