Vulnerability Description
Interpretation of untrusted input in template engine in GBIF Integrated Publishing Toolkit versions before 3.3.4 allows remote authenticated attackers to access server-side files and state via template injection
Related Weaknesses (CWE)
References
- https://github.com/gbif/ipt/issues/3118
- https://github.com/mandiant/Vulnerability-Disclosures/blob/master/2026/MNDT-2026
- https://www.gbif.org/ipt
FAQ
What is CVE-2026-71880?
CVE-2026-71880 is a documented vulnerability. Interpretation of untrusted input in template engine in GBIF Integrated Publishing Toolkit versions before 3.3.4 allows remote authenticated attackers to access server-side files and state via templat...
How severe is CVE-2026-71880?
CVSS scoring is not yet available for CVE-2026-71880. Check NVD for updates.
Is there a patch for CVE-2026-71880?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.