PT-2026-69101 · Testlink · Testlink

·

CVE-2026-70561

·

Published

2026-08-07

·

Updated

2026-08-07

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions TestLink versions prior to 1.9.21
Description An insecure direct object reference (IDOR) exists where authenticated users, including those with low-privilege guest accounts, can read arbitrary attachments. By providing an integer attachment ID to the 'attachmentdownload.php' endpoint, an attacker can bypass project and role authorization checks. This allows the enumeration of sequential IDs to retrieve sensitive files, such as test specifications, requirements documents, and execution evidence, from private projects regardless of the user's membership.
Recommendations Update TestLink to a version newer than 1.9.20. As a temporary mitigation, restrict access to the 'attachmentdownload.php' handler.

Exploit

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-70561

Affected Products

Testlink