CVE-2026-71518
Typemill before 2.26.0 contains an authorization bypass vulnerability in the media file download route that allows unauthenticated attackers to access restricted files by submitting path-equivalent URL variants. Attackers can substitute normalized path forms such as dot-slash prefixes, double slashes, or percent-encoded sequences to pass role-based restriction checks while the filesystem resolves the request to the protected file, enabling unauthorized file download without credentials.
- Affected products
- Typemill
- CVSS 4.0
- 8.7 HIGH
- CVSS 3.1
- 7.5 HIGH
- Weakness
- CWE-863
- NVD status
- Received
- Published
- 2026-08-17
CVE-2026-71518 at NVD
1 known exploit for CVE-2026-71518
Proof-of-concept code and exploit modules indexed by Sploitus