CVE-2026-71879: Authentication bypass in Integrated Publishing Toolkit
Missing authentication in initial setup functionality left exposed until first reboot in GBIF Integrated Publishing Toolkit versions before 3.3.4 allows remote authenticated attackers to gain administrative control via authentication bypass
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
GBIF Integrated Publishing Toolkitto a version that resolves this vulnerability.Fixed in 3.3.4
Event History
Frequently Asked Questions
Which deployments are exposed?
Systems running GBIF Integrated Publishing Toolkit versions before 3.3.4 are affected if they are in the initial setup state and have not yet undergone their first reboot. The issue can be exploited remotely during that exposure window.
What does an attacker need, and what access can they obtain?
The advisory states that an attacker must be remotely authenticated. Successful exploitation bypasses authentication and can result in administrative control.