SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-71880

HIGH · CVSS 7.6 EPSS 0.38% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-18 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The GBIF Integrated Publishing Toolkit versions prior to 3.3.4 are vulnerable to template injection due to improper handling of untrusted input, enabling remote authenticated attackers to access sensitive server-side files and state. This high-severity vulnerability poses a significant risk to the confidentiality and integrity of the system. Organizations utilizing affected versions should prioritize patching to mitigate potential data breaches and unauthorized access.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-71880
Severity
HIGH
CVSS
7.6
EPSS
0.38%

Original NVD Description

Interpretation of untrusted input in template engine in GBIF Integrated Publishing Toolkit versions before 3.3.4 allows remote authenticated attackers to access server-side files and state via template injection