Description
Missing authentication in initial setup functionality left exposed until first reboot in GBIF Integrated Publishing Toolkit versions before 3.3.4 allows remote authenticated attackers to gain administrative control via authentication bypass
Published: 2026-08-18
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

GBIF Integrated Publishing Toolkit (IPT) has a missing authentication check during its initial setup process. Until the first reboot, the tool can be accessed without credentials, and a remote attacker can reach the administrative console. By exploiting this oversight, an attacker can obtain full administrative control. The flaw is classified as CWE‑288 (Improper Authentication).

Affected Systems

GBIF Integrated Publishing Toolkit versions prior to 3.3.4 are affected. The vulnerability is present on all supported platforms running these releases.

Risk and Exploitability

The CVSS score of 9.1 indicates a critical severity. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector involves a remote attacker with network connectivity to the IPT instance, as the description specifies remote authentication bypass; this is inferred from the mention of remote attackers gaining control. Exploitation is only possible until the first reboot, after which authentication enforcement is enabled and the window closes.

Generated by OpenCVE AI on August 18, 2026 at 21:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade GBIF Integrated Publishing Toolkit to version 3.3.4 or later to restore authentication during initial setup.
  • If a patch cannot be applied immediately, restart the IPT service or reboot the host to trigger authentication enforcement and close the vulnerable window.
  • Restrict external network access to the IPT web interface during the initial configuration period by placing it behind a firewall or VPN, ensuring only trusted users can interact before the first reboot.

Generated by OpenCVE AI on August 18, 2026 at 21:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 18 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 18 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Description Missing authentication in initial setup functionality left exposed until first reboot in GBIF Integrated Publishing Toolkit versions before 3.3.4 allows remote authenticated attackers to gain administrative control via authentication bypass
Title Authentication bypass in Integrated Publishing Toolkit
Weaknesses CWE-288
References
Metrics cvssV4_0

{'score': 9.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Mandiant

Published:

Updated: 2026-08-18T19:29:12.627Z

Reserved: 2026-08-07T22:38:10.919Z

Link: CVE-2026-71879

cve-icon Vulnrichment

Updated: 2026-08-18T19:29:02.173Z

cve-icon NVD

Status : Received

Published: 2026-08-18T18:19:32.960

Modified: 2026-08-18T20:17:25.180

Link: CVE-2026-71879

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-18T21:30:04Z

Weaknesses
  • CWE-288

    Authentication Bypass Using an Alternate Path or Channel