PT-2026-77272 · Gbif+1 · Integrated Publishing Toolkit+1

CVE-2026-71880

·

Published

2026-08-18

·

Updated

2026-08-18

CVSS v4.0

7.6

High

VectorAV:N/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions GBIF Integrated Publishing Toolkit versions prior to 3.3.4
Description Remote authenticated attackers can access server-side files and state through template injection. This occurs because the template engine improperly interprets untrusted input.
Recommendations Update to version 3.3.4 or later.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-71880

Affected Products

Integrated Publishing Toolkit
Ipt