CRITICAL
GBIF
CVE published 2026-08-18
CVE-2026-71878
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-18T18:19:32.817Z and has not been modified since then. The GBIF Integrated Publishing Toolkit versions before 3.3.4 contain a critical vulnerability (CVE-2026-71878) that allows remote authenticated attackers to gain administrative control due to missing authentication in initial setup functionality [truncated]