CVE-2026-71878EPSS p57.0%

CVE-2026-71878CVE-2026-71878

Description

Missing authentication in initial setup functionality left exposed after initial setup is completed in GBIF Integrated Publishing Toolkit versions before 3.3.4 allows remote authenticated attackers to gain administrative control via authentication bypass

Scoring

EPSS0.86% probability of exploitation · percentile 57.0% · 2026-10-05T12:00:23Z
Last modified2026-08-31
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.