CVE-2026-71878: Gbif Integrated Publishing Toolkit
Critical severity, CVSS 9.2. EPSS: 0.9% chance of exploitation in the next 30 days.
Missing authentication in initial setup functionality left exposed after initial setup is completed in GBIF Integrated Publishing Toolkit versions before 3.3.4 allows remote authenticated attackers to gain administrative control via authentication bypass
Affected products
- Gbif Integrated Publishing Toolkit: before 3.3.4 (fixed in 3.3.4)
Published 2026-08-18. Last modified 2026-08-31.