CVE-2026-71879: Gbif Integrated Publishing Toolkit

Critical severity, CVSS 9.1. EPSS: 0.9% chance of exploitation in the next 30 days.

Missing authentication in initial setup functionality left exposed until first reboot in GBIF Integrated Publishing Toolkit versions before 3.3.4 allows remote authenticated attackers to gain administrative control via authentication bypass

Affected products

  • Gbif Integrated Publishing Toolkit: before 3.3.4 (fixed in 3.3.4)

Published 2026-08-18. Last modified 2026-08-31.