What is CVE-2026-71518?
Typemill versions prior to 2.26.0 contain an authorization bypass vulnerability in the media file download route. This allows unauthenticated attackers to access restricted files by submitting path-equivalent URL variants, such as dot-slash prefixes. Upgrading to Typemill version 2.26.0 or later is recommended.
Azərbaycanca: Typemill-in 2.26.0-dən əvvəlki versiyalarında media fayl yükləmə marşrutunda avtorizasiya bypass zəifliyi mövcuddur. Bu, autentifikasiya olunmamış hücumçulara path-equivalent URL variantları (məsələn, dot-slash prefixləri) təqdim etməklə məhdudlaşdırılmış fayllara giriş imkanı verir. Typemill-i dərhal 2.26.0 və ya daha yuxarı versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-863
FAQ2
Which versions of Typemill are vulnerable to the CVE-2026-71518 authorization bypass?
Typemill versions prior to 2.26.0 are vulnerable to this flaw.
How can an unauthenticated attacker exploiting CVE-2026-71518 gain access to restricted files?
An attacker can gain access to restricted files by submitting path-equivalent URL variants, such as dot-slash prefixes.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.