CVE-2026-88916: Admin Access Bypass via Header Fallback in TÜBİTAK ULAKBİM's UlakPDF
Published Sep 24, 2026
·Updated
Incorrect Authorization vulnerability in TÜBİTAK ULAKBİM UlakPDF allows Privilege Escalation.
This issue affects UlakPDF: through 09092026.
Affected Software
1 affected component
TÜBİTAK ULAKBİM UlakPDF<=09092026
Event History
Sep 24, 2026
CVE Published
via MITRE·12:49 PM
Data Sourced
via MITRE·12:49 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·01:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What access does an attacker need to exploit this issue?
The vector indicates that an attacker needs low-level privileges before exploitation. The issue is remotely reachable and does not require user interaction, but it has high attack complexity.
2
What is the potential impact if exploitation succeeds?
Successful exploitation can allow privilege escalation and may result in high confidentiality and integrity impact. No availability impact is indicated.
3
Which UlakPDF versions are affected?
The supplied advisory states that UlakPDF is affected through 09092026. No fixed version or patch version is provided in the available data.