THREAT OPS › Threat News › [NVD] CVE-2026-71518 (HIGH 7.5) — Typemill before 2.26.0 contains an authorization bypass vulnerability in the media file download route that allows unauthenticated attackers to access restricted files by submitting path-equivalent URL variants. Attackers can substitute normalized path forms such as dot-slash pre
[NVD] CVE-2026-71518 (HIGH 7.5) — Typemill before 2.26.0 contains an authorization bypass vulnerability in the media file download route that allows unauthenticated attackers to access restricted files by submitting path-equivalent URL variants. Attackers can substitute normalized path forms such as dot-slash pre
CVE-2026-71518 CVSS: 7.5 HIGH Published: 2026-08-17T21:16:48.277
Typemill before 2.26.0 contains an authorization bypass vulnerability in the media file download route that allows unauthenticated attackers to access restricted files by submitting path-equivalent URL variants. Attackers can substitute normalized path forms such as dot-slash prefixes, double slashes, or percent-encoded sequences to
MITRE ATT&CK techniques
- CredentialsT1589.001
Indicators of compromise
- CVE-2026-71518cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-71518