CVE-2026-71878: Authentication bypass in Integrated Publishing Toolkit
Missing authentication in initial setup functionality left exposed after initial setup is completed in GBIF Integrated Publishing Toolkit versions before 3.3.4 allows remote authenticated attackers to gain administrative control via authentication bypass
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
GBIF Integrated Publishing Toolkitto a version that resolves this vulnerability.Fixed in 3.3.4
Event History
Frequently Asked Questions
Which deployments are exposed?
Instances running a version before 3.3.4 are affected if the initial setup functionality remains exposed after setup has been completed.
What does an attacker need to exploit this issue?
An attacker must be remote and authenticated. Exploitation abuses the authentication bypass in the initial setup functionality to obtain administrative control.
What is the remediation?
Upgrade GBIF Integrated Publishing Toolkit to version 3.3.4 or later. The provided information does not specify a workaround if upgrading cannot be done immediately.