CVE-2026-88907: SAML ePPN Attribute Validation Bypass in TÜBİTAK ULAKBİM's UlakPDF
Published Sep 24, 2026
·Updated
Incorrect Authorization vulnerability in TÜBİTAK ULAKBİM UlakPDF allows Authentication Bypass.
This issue affects UlakPDF: through 09092026.
Affected Software
1 affected component
TÜBİTAK ULAKBİM UlakPDF<=09092026
Event History
Sep 24, 2026
CVE Published
via MITRE·12:46 PM
Data Sourced
via MITRE·12:46 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·01:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which UlakPDF versions are affected?
The issue affects TÜBİTAK ULAKBİM UlakPDF through version 09092026.
2
Does exploitation require an authenticated account or user interaction?
The provided CVSS vector indicates that exploitation requires no privileges and no user interaction, and can be attempted over the network. It also indicates high attack complexity.